Can any one help to understand & use of below command in eval
index=_internal | eval Mahesh=max(1, 3, 6, 7, "foo", field)
@maheshsat, please add a context as to why and where is this being applied. What are the typical values in field
? Is it numeric or string?
Max will pull the highest in the list. Other way to analyze would be of you reverse sorted values, which value will be the first.
| makeresults
| eval field=1000
| map search="| makeresults
| eval data=\"1,3,6,179,foo,$field$\""
| makemv data delim=","
| mvexpand data
| sort - data
| head 1
PS: Take out head 1
command o see ranking of each values. Also change field
value to its max value(string or number) to be added to the query.