I have events that are performance metrics taken over time. It includes fields like the sample value and object it pertains to. I want to display a table with that object and the most recent sample value for each object. Right now a query that shows all values would look something like this:
index=custom | table _time, account, metric_name, metric_value
I would like to do a query like
index=custom metric_name=utilization | blah blah
and get a table that includes account, metric_name, metric_value, time, but only show the most recent value for each account/metric_name.