Can someone please explain me what does the following query will do step by step ?
type=hosts | sort -recentTime | convert ctime(recentTime) as Latest_Time
thank you
That query is not valid. I believe the correct version would be
| metadata type=hosts | sort -recentTime | convert ctime(recentTime) as Latest_Time
which retrieves a list of host names from the default indexes, sorts them from most-recently used to least-recently used, then converts the recentTime field from epoch format into text and renames it to Latest_Time.