Hello! Rather than manually specifying the indexes I want to perform this heartbeat query on, I was wondering if there was a way to input a .csv lookup instead.
| tstats latest(_time) as latest where index="index1" OR index="index2" earliest=-24h by index | eval recent = if(latest > relative_time(now(),"-1m"),1,0), realLatest = strftime(latest,"%c") | where recent=0 | fields- recent, latest | rename realLatest as "Last Event Timestamp"
The .csv would just contain a bunch of index names that we'd want to monitor, but so far I haven't been able to get around the fact that tstats must come first, and that the index argument does not accept complex inputs.
Thanks!
... View more