(imported comment written by upinya91)
jessewk
I can think of 2 ways right off the bat… chose the line with the highest line number, or parse out the time stamps and choose the maximum. The relevance for the time stamp version will be a little more straightforward. If you post an example line I can give you an exact relevance query, but in pseudo code it would look like this:
maximum of ({relevance to extract time stamp string} as time) of lines whose (it contains “Update Finsihed”)…
Here’s the line from the log file, for example:
8/28/2008 9:01:52 AM NT AUTHORITY\SYSTEM Update Finished