I have a table that shows the host name, IP address, Virus Signature, and Total Count of events for a given period of time. I would like to add a field for the last related event. The results would look similar to below (truncated for brevity):
Last_Event Host_Name Count
9/14/2016 1:30PM ABC123 50
9/14/2016 1:30PM DEF432 3
Appreciate the help,
Thanks,
... | stats c as Count latest(_time) as _time by Host_Name
Thanks -- the latest time is appearing and with the total count of events! The last thing I needed was changing the order of the fields and that was done by adding ..| table "_time","Count","Host_Name","etc.."