How to know the last event's time from each of the hosts in the system?. The output can be of the below format?
host1|datetime
host2|datetime
thank you
Since host is an indexed field you can use
| tstats latest_time by host where index=XXX
@PickleRick , sorry, I am a normal user and have access to only specific index. Running the above command is failing.
Error in 'tstats' command: Invalid argument: 'index=indexname
Try without the whole where condition.
see the below error
I rarely do the earliest/latest and so on 🙂
Probably max(_time) or latest(_time) will be what you need (they are not the same thing though!). As an excercise, think about the difference between max(_time) and latest(_time) 😉