I am trying to get a report of all hosts that have not reported any events in the last 2 hours. I am using:
| metadata type=hosts | search totalCount >0 AND lastTime < now-2h
It only reports hosts that have a totalCount >0 yet it ignores the lastTime qualifier.
Any suggestions?
Thank you!
... View more