Hello
I have below logs in last 60 mins
log1: ABC=1,DEF=2,GHI=3
log2:ABC=0,DEF=0,GHI=3
while executing my query for last 60 mins
i am getting below result
ABC=1,DEF=2,GHI=3
ABC=0,DEF=0,GHI=0
But i want only latest log result as like below
ABC=1,DEF=2,GHI=3
...
| head 1
could any please help me to find the solution.
Try limiting the number of events with head
index="cx_aws" source="notification-service"
| head 1
| spath ...
I am not sure if this is the right query but it seems to be the one from your image. The point is that head will reduce the number of events from the base search, in this case to 1 i.e. the latest event
Check out the dedup command.
where should i use this command
I kept dedup command at the end but it didnt worked