Hello,
I have a list of users and the time they entered a building.
I'm trying to find the earliest + latest time.
This is the code that i have:
host="myhost"
| table first_name last_name qr_code created_date date_mday
| sort by date_mday
| dedup qr_code
| stats earliest(created_date) as created_date
the stats line breaks my code.
Any suggestions or hints?
Thank you
Try something like this -
host="myhost"
| dedup qr_code
|eventstats earliest(created_date) as created_date
| table first_name last_name qr_code created_date date_mday
| sort by date_mday
Remember, Splunk treats time as numbers. Depending on how your created_date field, looks like you may have to convert epoch/unix times.