Hi all,
How to form a table to display latest raw event for field mentioned by index and source type.
This is the output am planning as below:
The maximum I am able to reach is listing field values but not raw events containing that field.
Any help is appreciated.
Thanks in Advance
Do you need this for a few specific fields, known up front, or are you looking for a more generic solution somehow?
If some specific known fields, I guess something along the lines of below should work.
index=* Field_1=*
| stats latest(_raw) as F1_raw by index,sourcetype
| append [
index=* Field_2=*
| stats latest(_raw) as F2_raw by index,sourcetype
]
| stats values(F1_raw) as Field_1 values(F2_raw) as Field_2 by index,sourcetype