Another possible approach that doesn't require a subsearch. Use if to set a variable to 1 if the time is within the last day and 0 if it is older. Sum the variable to get a count of events that happened in the last 24 hours and count all the events. If all of the events are new (AllCount=NewCount), then the event has only happened in the last 24 hours.
Example:
table _time host Code |
eval cutOffTime=relative_time(now(),"-24h"), New=if (_time>cutOffTime,1,0) |
stats sum(New) as NewCount count as AllCount by host Code |
where AllCount = NewCount
... View more