Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Need to display the latest event as a result

$
0
0
Search query :1 index="main" earliest=06/01/2019:00:00:00 latest=now | stats first(status) by src destination port Search query : 2 index="main" earliest=06/01/2019:00:00:00 latest=now | stats latest(status) by src destination port I have used first and latest command in stats. There 2 status in the events like "STATE UP" and "STATE DOWN". I would like fetch the latest event with latest status field. But if i am searching the above query it is showing the both.(STATE UP and STATE DOWN). I would like display the latest either "status up or status down". Someone help me to find the solution. Current Results: src destination port first(status) XXX YYY 443 State DOWN XXX YYY 443 State UP

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>