Getting Data In

How to get the latest timestamp by host?

ppatkar
Path Finder

I need to list all the hosts with their latest Splunk event timestamps in YYYY-MMM-DD HH24:MI:SS format .
Below seems to be suffice , however I am unable to change the date & time format for required results :

tstats latest(_time) where index=abc by host

Any help or insights is appreciated.

0 Karma
1 Solution

DavidHourani
Super Champion

Hi @ppatkar,

Does something like this work for you ?

| tstats latest(_time) AS _time where index=abc by host | eval _time=strftime(_time,"%m/%d/%y %H:%M:%S")

Cheers,
David

View solution in original post

DavidHourani
Super Champion

Hi @ppatkar,

Does something like this work for you ?

| tstats latest(_time) AS _time where index=abc by host | eval _time=strftime(_time,"%m/%d/%y %H:%M:%S")

Cheers,
David

ppatkar
Path Finder

Thanks David, after searching for similar posts could manage the below :

| tstats latest(_time) AS latest where index=abc by host | convert timeformat="%Y-%m-%d %H:%M:%S" ctime(latest)

DavidHourani
Super Champion

awesome, glad to know you found a solution !

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...