I'm looking for help creating a search that returns all events from the last log indexed.
This is what i've tried but it doesnt return the events just the source.
| get all sources from metadata | sort all sources desending by time and only return the last one | join the main index on the source columns
| metadata type=sources | sort 1 recentTime desc
| fields source
| join source [search index=main | fields source]
So close ...
* [ | metadata type=sources | sort 1 recentTime desc | fields source ]
The subsearch in the [ .. ] expands to ( source=your_latest_source )
So the main search is
* ( source=your_latest_search )
Good to know. For the record, you dont have to send extra rep, accepting the answer is the normal way to do that. Cheers
That fixed it. Thanks!