Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to extract latest event for unique account numbers?

$
0
0
Hello, I'm trying to extract some fields for the latest event based on unique account numbers. I've tried using latest(field) but the issue I'm running into is for example: Event date: 9/20/2019 field_of_interest: NULL 9/19/2019 field_of_interest: "04/09/2019" 9/18/2019 field_of_interest: NULL When I do latest(field_of_interest) I'm being returned "04/09/2019" when I want to retrieve the NULL from 09/20/2019. I've read other answers that lead me to believe I may need to do latest(_raw) and look for the field with a regex but maybe there is another approach? Thank you in advance for your help in this, I hope the question is clear!

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>