Splunk Search

mstats latest(_time) not working

simpkins1958
Contributor

I am not able to get the latest (or earliest) _time values using mstats.

| mstats sum(bytes) latest(_time)
where index=metrics_app_dest_survey by app_name

is returning:

alt text

0 Karma
1 Solution

simpkins1958
Contributor

Misunderstanding on my part. I thought we could get the earliest/latest time value. Now I see that latest()/earliest() are for the metric value not _time value.

In 7.2 there are new time functions latest_time() and earliest_time() that get the time values.

View solution in original post

simpkins1958
Contributor

Misunderstanding on my part. I thought we could get the earliest/latest time value. Now I see that latest()/earliest() are for the metric value not _time value.

In 7.2 there are new time functions latest_time() and earliest_time() that get the time values.

Vijeta
Influencer

You can get latest(_time), the screenshot you shared shows latest(time) as column name. It should be latest(_time) unless you are renaming _time to time

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...