I have events like
Event EndDateTime
Launch 2017-05-16 13:00:00
.
.
.
Open 2017-05-16 13:00:30
I want to subtract time between these two events.
I want to implement something like
index="myindex" sourcetype="mysourcetype" | transaction host startswith="Launch" endswith="Open"|convert timeformat="%Y-%m-%d %H:%M:%S" mktime(EndDateTime)| eval difference=[subtract EndDateTime where Event=Open - EndDateTime where Event=Launch| chart avg(difference)
I just can't understand how can I work with the eval part about calculating difference.
So I basically did this and got what I wanted:
transaction host startswith="Launch" endswith="Open" | streamstats sum(TimeSec) as dur window=1 |
Thank you for your support. I had been such a stupid to not observe this earlier.