Hi,
My source file gets updated every 5 minutute . How to chart values of a field by the latest source file?
Assuming your updated source file gets indexed every 5 minutes- meaning you will have new events indexed every 5 minutes, what you can try out is - <your search> |eventstats max(_time) as time | where _time=time| <rest of your query>
This ensures that ONLY the latest time events are being picked up for further processing after the where condition