Open wchaparro opened 4 months ago
Pinging @elastic/es-analytical-engine (Team:Analytics)
Do we want smth different than this? https://www.elastic.co/guide/en/elasticsearch/reference/master/esql-functions-operators.html#esql-agg-max
Good catch @bpintea updated the title/desc
This would be incredible for us coming from Splunk and missing the latest()
function... if there is ever some prototype work on this that you'd like feedback for, definitely let me know.
Hey @IanLee1521 thanks for the offer. We'd like to do this someday but no specific plans yet. We'll let you know if we need any requirements clarification or feedback. I assume first and last would be like earliest and latest, respectively.
Support aggregate functions - BY <@timestamp>)`
FIRST(<field> BY <@timestamp>)
and LAST(