Reputation: 384
I am trying to get the latest event timestamp for each host, google search found below:
|metadata type=hosts | table host, lastTime
it seems worked, returned the host and the timestamp, however, the timestamp is an big integer number, how do I convert to local time?
also how do I filter it so it only return certain hosts?
Thanks.
Upvotes: 0
Views: 1416
Reputation: 228
For the time formatting - try this post: Splunk convert extracted field in currently milliseconds to HH:MM:SS
For the host search - you should be able to | search host=XXXX
Upvotes: 1