Hi All,
I am looking to extract data from index search for below query :-
need timestamp of 1st event in the day for last 30 days in a particular index and sourcetype.
Can someone help with the query to get desired output ?
index=whatever sourcetype=whatever | timechart span=1d earliest(_raw) as _raw
index=whatever sourcetype=whatever | timechart span=1d earliest(_raw) as _raw
Thanks, it worked