Finds the largest number for the specified field over a set of events. Result is returned in a field named _max.
Function Traits: Aggregate
The parameter name for field
can be omitted; the following forms are equivalent:
logscale
max("value")
and:
logscale
max(field="value")
max()
Examples
Return what was the maximum responsetime:
logscale
max(responsetime)
Filter for events in the repository with maximum responsetime values greater than 5 seconds:
logscale
max(responsetime)
|_max> 5