Splunk Search

Get the last Json Inserted document

sibbsnb
Path Finder

I have an Index where i store huge Json documents. I want the last document inserted which contains the latest state. What is the most efficient command.

1) tail 1
2) latest
3) dedup

Tags (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Since Splunk searches backward in time, tail will give you the oldest entry rather than the latest. I prefer to use 'head 1' to find the most recent event.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Since Splunk searches backward in time, tail will give you the oldest entry rather than the latest. I prefer to use 'head 1' to find the most recent event.

---
If this reply helps you, Karma would be appreciated.

sibbsnb
Path Finder

Great, thanks a lot. That helps. So i don't even need to mention any time modifiers. Just do head 1 and i get the latest Json.

0 Karma

somesoni2
Revered Legend

If you just want one records which was inserted/indexed recently, head is the command you need. If you need last indexed records by a field (say host or user) then dedup or stats latest can be used.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...