I have 2 indexes( a summary index and a normal index).
I want to search the summary index for all time but want to get only the latest file from the other index i.e time range should be last 30 days, in the same query.
something like this -
(index=dummyindexsummary reportname=dummyreport) OR (index="dummy_index" (sourcetype="abc" host="auirvcbpw001" source="abc" ))
first query should execute for all time whereas second one should excecute for the last 30 days(somehow should return only the latest file) , in the same query.
Can someone please help me ? Thanks in advance!
HI to this i have one query, for 2nd index i want to select the latest source file , how can we achieve that..
i used |stats latest(source) as source but getting error while running the script