Getting Data In

how to pick values by latest source

Mohsin123
Path Finder

Hi,

My source file gets updated every 5 minutute . How to chart values of a field by the latest source file?

0 Karma

Sukisen1981
Champion

Assuming your updated source file gets indexed every 5 minutes- meaning you will have new events indexed every 5 minutes, what you can try out is - <your search> |eventstats max(_time) as time | where _time=time| <rest of your query>
This ensures that ONLY the latest time events are being picked up for further processing after the where condition

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!