Finds the largest number for the specified field over a set of events. Result is returned in a field named _max.
The parameter name for
field can be omitted; the following forms are equivalent:
Return what was the maximum responsetime:
Filter for events in the repository with maximum responsetime values greater than 5 seconds:
max(responsetime) |_max> 5