maxif

Synopsis

Calculates the maximum of the values in a specified column in the search query results based on a query to be executed on the record.

Syntax

maxif [column_name] “[search_query]”

Required Arguments

column_name

Syntax: <character string>

Description: The name of a column header that has numeric values

search_query

Syntax: <character string>

Description: The search query to be executed on the record

Optional Arguments

None

Description

From all the search query results, returns the maximum value in the specified column_name.

Examples

Example 1:  

* in log.access | maxif Bytes Sent "status=200"

Returns the maximum value of the column Bytes Sent in the events from access log only if the value of column status is 200.

Example 2:  

* in log.iis log | maxif time-taken "cs-host contains http" | group by c-ip 

From the events from log.iss log that have the text http in their cs-host column, finds and returns the maximum value in the time-taken column per each c-ip column value.