Mar 16 2020
07:11 AM
- last edited on
Apr 08 2022
10:20 AM
by
TechCommunityAP
Mar 16 2020
07:11 AM
- last edited on
Apr 08 2022
10:20 AM
by
TechCommunityAP
Hello,
I try to build a query that find the last state of a Windows service, for example 'WMI Performance Adapter' (See attached image).
I would like to get only the last event/service state for each computer but i cannot find the proper operators.
Thanks for help :)
Mar 16 2020 08:35 AM
Solution
This would be an example using arg_max
Event
| where EventID == 7036
| summarize count(), last_record = arg_max(TimeGenerated, *) by Computer
Mar 16 2020 08:47 AM
Many thanks, it works like a charm :)
Mar 16 2020 08:35 AM
Solution
This would be an example using arg_max
Event
| where EventID == 7036
| summarize count(), last_record = arg_max(TimeGenerated, *) by Computer