HI I have two time stamps like "2017-01-30T19:22:39Z" "2017-01-29T19:17:33Z"
From the above two timestamps I wan to get latest timestamp i.e 2017-01-30T19:22:39Z, please help me
How about this.
Convert them in epoch time and then do the selection with an IF clause. Select whichever is larger.
Just shared the logic, see if that works for you.
... | eval LatestTS = if(strptime(TS1,"%Y-%m-%dT%H:%M:%S%Z")>strptime(TS2,"%Y-%m-%dT%H:%M:%S%Z"), TS1, TS2) | ...
haha you beat me with few seconds there, and you posted the exact query. Yes, this should work for the OP.