I want to compare two values of _time field and tell which event occurred first.
Convert 2 fields to epoch time then do a comparison using where command to list only events which occurred first.