I'm trying to return the associated fields based on a stats command. My stats command determines the minimum field value based on two other fields. I need the remaining fields associated with the record that has this minimum value.
For example, my data looks like this:
Project RequestID TaskID Resolution
A 1 1 Fixed
A 1 2 Withdrawn
A 1 3 Deleted
B 2 4 On Hold
B 2 5 Created
I want to return a table like this:
Project RequestID TaskID Resolution
A 1 1 Fixed
B 2 4 On Hold
How is this achieved since stats requires you to either use a function or group by to return the values? I don't want either, I just need the associated fields based on the minimum value of another field.
Thanks!!
Try this:
<search that produces the table above> | eventstats min(TaskID) as min_task min(RequestID) as min_req by Project | where (RequestID=min_req AND TaskID=min_task) | fields - min*
Try this:
<search that produces the table above> | eventstats min(TaskID) as min_task min(RequestID) as min_req by Project | where (RequestID=min_req AND TaskID=min_task) | fields - min*