Thanks to all that responded. Below is what I ended up with. It still has some bad apples but that is not because of the search but rather something else with the system or data that is not consistent with all of the other systems. I mostly notice issues with systems that are Server 2012 or 2016. Out of roughly 300 systems they are only a few bad apples. index=index type="Windows:UpdateList" | eval Installedon=strptime(Installedon,"%m/%d/%Y") | stats latest(Installedon) as LastUpdate by host | where LastUpdate<=relative_time(now(), "-30d") | eval LastUpdate=strftime(LastUpdate,"%m/%d/%Y") | sort LastUpdate
... View more