hello
when I execute the request below, i want to display only the last event without playing with token time or doing a dedup time
index="windows-wmi" sourcetype="wmi:diskdrive" | table host Caption DeviceID FirmwareRevision Status
how to do please?
You could use the tail command:
index="windows-wmi" sourcetype="wmi:diskdrive" | table host Caption DeviceID FirmwareRevision Status | tail 1
@jip31 you should define whether you are interested in last event or latest event.
For latest event you should perform <yourCurrentSearch> | head 1
Hello niketnilay i dont know if you have seen my comment before : for one host i have To events every hour. So for every host i need the Two last Event. Head 1 works only for one host and one event
If that is the case then you need stats/dedup by each hour so that you can identify two events. Any reason why you dont want to use either one?
Is there a way to filter each of the two events per hour uniquely?
@jip31
|sort _time
@harishalipaka although your answer might not be what @jip31 might be looking for, | reverse
will work faster than | sort
command.