How to place the "earliest and latest " functions ? Can anyone provide an example of such a query with the output !
You can find them here:
http://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/Eventorderfunctions#earliest.28X.2...
Remember, since both these functions works on chronological occurrence of events/fields, they work accurately if the field _time is available in the results (before you run the stats command).