Hi,
We have a sourcetype type called "WinHostMon" and many hosts report into it. Does anyone have any SPL laying around that would allow me to query the last time a host checked in with that particular Sourcetype?
Like this:
| tstats max(_indextime) AS time_event_was_indexed max(_time) AS time_event_happened WHERE index="*" AND sourcetype="WinHostMon" BY host
| sort 1 - time_event_was_indexed
Hi,
Try the below SPL.Modify based on your need.
|tstats count where sourcetype=WinHostMon by host,_time,sourcetype
|table host,sourcetype,_time
|sort - _time
|head 1