I have many agent versions and each row is displayed as the different version... Like the query is telling it to do.
I need help in the sense of would like to truncate evey period and digit to the single version digit.
To look like this:
you can use substr eval function
| eval version=substr(version,1,1)
index=_internal sourcetype=splunkd group=tcpin_connections version=* os=* arch=* build=* hostname=* source=*metrics.log | stats latest(version) as version,latest(arch) as arch,latest(os) as os,latest(build) as build by hostname | eval version=substr(version,1,1) | join hostname [ | metadata type=hosts index=* | eval last_seen_hours=(now()-lastTime)/60/60 | table host, last_seen_hours | rex field=host "(?<hostname>[^\.]+)" | fields - host ]