I manage to extract the data from Splunk below:
ID SignalStrength TimeStamp
01 3 09:00:05
01 0 09:30:00
02 0 09:00:05
02 0 09:30:00
02 3 09:55:00
But I wanted to reduce it further to only get the last record in the hour, like this:
ID SignalStrength TimeStamp
01 0 09:30:00
02 3 09:55:00
I tried this:
| stats max(Timestamp) by ID, SignalStrength
but it gave me the maximum on the day not per hour.
Try this:
| bin _time span=1h | stats max(Timestamp) by ID, SignalStrength, _time