I am using the below rex command and then finding out the latest and earliest time .
Search |rex ".*execution.date=(?\w+)" | rex "execution.date=(?\w+)}] and the following status: [COMPLETED]" |
stats earliest(_time) as First latest(_time) as Last by executiondate |
But instead of earliest time I need 2nd Latest time or penultimate time. How will I get? Thanks in Advance 🙂
Try like this
your current search with rex statements and before stats | sort 2 -_time by executiondate |stats earliest(_time) as First latest(_time) as Last by executiondate
your search that gets the records you want with _time and executiondate | eventstats count as eventcount, latest(_time) as Last by executiondate | where _time != Last OR eventcount=1 | stats earliest(_time) as First, latest(_time) as Penultimate, latest(Last) as Last by executiondate
eventstats puts the
Last figure where you can save it and get to it, on every record for each
where kills the very last date, but you already have saved what it said in
stats then calculates the
Penultimate times. If there is only one event, then all three values are the same. If there are two, then
Penultimate are the same.
I am gettting latest(last) time as penultimate time
Be sure to mark your code as code, so the interface will not delete parts of it.