Splunk Search

First Everyday

reverse
Contributor

There are multiple CSVs which I generate on a daily basis.
Each CSV has some critical data & has 2 columns - _time & XX
I JOIN all CSVs to generate graphs.
The common column in each CSV is _time.

Now lets say I have 2 CSVs.

1 _time & XX 
2 _time & YY

I need to find earlier time and corresponding XX when yy=100 (first apperance)on a daily basis.. as CSVs are there since last 2 months with all the required data.

How can i achieve that ?

Tags (1)
0 Karma
1 Solution

reverse
Contributor
| eval mytime=strftime(_time, "%Y%m%d") 
| where x=100| dedup mytime
|sort _time | head 50

View solution in original post

0 Karma

reverse
Contributor
| eval mytime=strftime(_time, "%Y%m%d") 
| where x=100| dedup mytime
|sort _time | head 50
0 Karma

reverse
Contributor
| stats first(_time) by x | where x=100

Not working

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...