I'd like to select the earliest events broken down by category.
i.e. I would like to see something like this:
error | stats earliest(_raw) as earliest_raw by error_category | ...
That pretty much gives me what I need, but it's a little inconvenient that 1) now I have to work off of "earliest_raw" and 2) the event list view doesn't show anything.
Is there a better way? What I'd really like to do is something like:
error | earliest by error_category | ...
aholzer's answer worked great:
error | dedup category sortby +_time | ...
Thanks!
aholzer's answer worked great:
error | dedup category sortby +_time | ...
Thanks!
I'm not sure how to use head/tail since I also need to group by category, but dedup:
dedup category sortby +_time
worked like a charm! Thanks!
You may want to consider using one of the following:
- dedup with a sort by time
error | dedup error_category sort by +_time
- the head command or the tail command depending how you want to look at your events
Just remember that you can perform checks on the field "_time" to get the earliest
Hope this helps