Getting Data In

how to pick values by latest source

Path Finder

Hi,

My source file gets updated every 5 minutute . How to chart values of a field by the latest source file?

0 Karma

Champion

Assuming your updated source file gets indexed every 5 minutes- meaning you will have new events indexed every 5 minutes, what you can try out is - <your search> |eventstats max(_time) as time | where _time=time| <rest of your query>
This ensures that ONLY the latest time events are being picked up for further processing after the where condition

0 Karma