Hi,
I am building an app for managing some network switches. One of the views I want to create has the same data list:
For a given period of time, grouped by host, the date of the last event that matches certain criteria.
I can do that easily with "| tail 1", but that only covers one host or query. With the stats command, I can easily find the number of events matched grouped by host, but I am struggling to find the last one only for every host.
Any ideas?
Many thanks!
How about:
... | stats last(_raw) by host
dedup host
It seems that once you do this you lose access to the fields and would have to parse it out manually. For example if you pipe the above to "| table _time" _time is empty. Any way around this?
so elegant... I love it... thanks!