Hi,
I want only return the latest event
The following seems to work so far. It is correct? No entirely sure what the sort criteria for Top is
Top limit=1 Color,TimeStamp,Bank,DX | table Color
No. The "top" command is used to find the most frequent value of the field specified, here you specify 4 fields, so we return the most common combination of these four fields.
You are looking for the "head" command: ... | head 1 | ...
No. The "top" command is used to find the most frequent value of the field specified, here you specify 4 fields, so we return the most common combination of these four fields.
You are looking for the "head" command: ... | head 1 | ...