I have a search which results in an event which has multiple instances of the field eltime.
Does anyone know how I can only display the largest value of the field eltime
did you tried:
|stats max(eltime) as largest_value_of_eltime.
If eltime is the result of a transaction command your transaction command should group all the values of eltime in a multi-value list. Then, you should be able to get the maximum. like for example:
|transaction eltime delim="," mvlist=eltime|eval maximum_eltime=max(eltime)|table maximum_eltime
Doesn't quite work the way I want it to. I want to determine the maximum value of eltime for each event (there are multiple instances of eltime for each event - This is because each event is an output of the transaction command)