# Find latest value of X for each term in Y - Splunk equivalent

**URL:** <https://discuss.elastic.co/t/find-latest-value-of-x-for-each-term-in-y-splunk-equivalent/217346>\
**Category:** Elasticsearch\
**Created:** [January 31, 2020, 10:15am UTC](https://discuss.elastic.co/t/find-latest-value-of-x-for-each-term-in-y-splunk-equivalent/217346 "2020-01-31T10:15:30Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![wiouser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wiouser/32/45741_2.png) [@wiouser](https://discuss.elastic.co/u/wiouser)\
**Post date:** [January 31, 2020, 10:15am UTC](https://discuss.elastic.co/t/find-latest-value-of-x-for-each-term-in-y-splunk-equivalent/217346/1 "2020-01-31T10:15:30Z")

</div>

Hi,

I have a time series data in an index.  
I am trying to find latest value of a field1 split by terms in field2.  
Then apply a filter example `field1=SUCCESS` and count the resulting terms.  
I just want to return only the final count.

I am from splunk background and exploring elasticsearch. In splunk I do  
`index | stats latest(field1) as latest_status by field2 | where latest_status="SUCCESS" | stats count`

Is there a equivalent for this in elasticsearch. Please help.

---

<div class="post-metadata">

**Author:** ![katara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/katara/32/60143_2.png) [@katara](https://discuss.elastic.co/u/katara)\
**Post date:** [January 31, 2020, 11:02am UTC](https://discuss.elastic.co/t/find-latest-value-of-x-for-each-term-in-y-splunk-equivalent/217346/2 "2020-01-31T11:02:56Z")

</div>

How are you pushing this data to ES?  
If its with Logstash,  
You can try this in your elasticsearch output.  
If your input is JDBC for example,  
Assuming your field2 is a time field,

```auto
input {
  jdbc {
    ...
    statement => "SELECT field1,field2 from yourtable where field2 > :sql_last_value"
    use_column_value =>true
        tracking_column =>field2
        tracking_column_type => "timestamp"
    last_run_metadata_path => "/Users/me/.logstash_jdbc_last_run" 
    ...
  }
}
output {
  elasticsearch {
    hosts => ["yourelasticIP"]
    index => "yourindex"
    action=>update
    document_id => "%{field1}"
    doc_as_upsert =>true
}
        stdout { codec => rubydebug }
}

```

Katara.

---

<div class="post-metadata">

**Author:** ![wiouser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wiouser/32/45741_2.png) [@wiouser](https://discuss.elastic.co/u/wiouser)\
**Post date:** [January 31, 2020, 11:39am UTC](https://discuss.elastic.co/t/find-latest-value-of-x-for-each-term-in-y-splunk-equivalent/217346/3 "2020-01-31T11:39:28Z")

</div>

Thanks for the reply. Field2 is not time. This is how my documents look like

{time, field1, field2}  
{03:00, T1, failure}  
{03:00, T1, success}  
{02:00, T1, failure}  
{02:00, T2, success}  
{01:00, T2, failure}

I want to find the latest status for every term in field1 and then count the number of success.

And it's not logstash and we cannot update existing documents for new status documents.

Thank you

---

<div class="post-metadata">

**Author:** ![katara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/katara/32/60143_2.png) [@katara](https://discuss.elastic.co/u/katara)\
**Post date:** [January 31, 2020, 11:59am UTC](https://discuss.elastic.co/t/find-latest-value-of-x-for-each-term-in-y-splunk-equivalent/217346/4 "2020-01-31T11:59:01Z")

</div>

Okay, How are you pushing the data to Es from your source?

---

<div class="post-metadata">

**Author:** ![wiouser](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wiouser/32/45741_2.png) [@wiouser](https://discuss.elastic.co/u/wiouser)\
**Post date:** [January 31, 2020, 12:05pm UTC](https://discuss.elastic.co/t/find-latest-value-of-x-for-each-term-in-y-splunk-equivalent/217346/5 "2020-01-31T12:05:58Z")

</div>

Through the index api.  
Whenever the validate function is called from client, the server processes it sends response back to client and logs in elasticsearch index through the rest api.

---

<div class="post-metadata">

**Author:** ![katara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/katara/32/60143_2.png) [@katara](https://discuss.elastic.co/u/katara)\
**Post date:** [January 31, 2020, 12:17pm UTC](https://discuss.elastic.co/t/find-latest-value-of-x-for-each-term-in-y-splunk-equivalent/217346/6 "2020-01-31T12:17:39Z")

</div>

Okay,  
You have to have \_timestamp enabled in ES.  
and then you can query the latest data.

```auto
{
  "query": {
    "match_all": {}
  },
  "size": 1,
  "sort": [
    {
      "_timestamp": {
        "order": "desc"
      }
    }
  ]
}

```

Is this something you are looking for?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2020, 12:17pm UTC](https://discuss.elastic.co/t/find-latest-value-of-x-for-each-term-in-y-splunk-equivalent/217346/7 "2020-02-28T12:17:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
