I have a search that tables certain values from my data fields, although i wish to create a new field on all events called Maximum that gets the latest value of a field called max and another called min
You can use eventstats:
index=_internal | eventstats max(date_second) AS MAX min(date_second) as MIN | table date_second,MAX,MIN
View solution in original post
Thanks for your response.
I used eventstats but I also wanted to get values from the search and table them as well.
Do you know how?
Could you provide the search and if possible some sample data?