I am trying to run the following search, which works fine from the regular Splunk search UI, but not in the Powershell interface...
| metadata type=hosts earliest=-1d
Using the Search_Splunk command I get...
Error in 'metadata' command: This command must be the first command of a search
If I remove the | the script completes without error but no data is returned, unlike in the UI where I get 600+ records.
Any clue as to what I am doing wrong? Greatly appreciate any assistance you can provide.
Thanks, Dan