I have different log files but the last line of each files are different and don't know what will come tomorrow. So, is there any specific regex form or command available that can easily identify the end line ??
Hi,
Assuming that timeseries of events is maintain, you can try this command:
index=<your_data_index_> | stats latest(_raw) AS "last line" by source
Hi,
Assuming that timeseries of events is maintain, you can try this command:
index=<your_data_index_> | stats latest(_raw) AS "last line" by source
Thanks p_gurav,
I have tried with your command and it's working properly as I want.
Happy to Help!!