Given data like:
_time, lastname
How would I do a count of lastname and display the most recent _time for that lastname on the same row of a results table?
--Mark
Like this:
index=YouShouldAlwaysSpecifyAnIndex AND sourcetype=AndSourcetypeToo
| stats count max(_time) latest(_raw) BY lastname
@mumblingsages ,
Try,
"your base search" |stats count , latest(_time) by lastname