Use transaction : startwith and endwith to capture one process within this log file.
Show the duration of this process for each host/source
| rex field=_raw "Process(?.*)"
| transaction ProcessName startswith="BEGIN" endswith="END"
| eval durationMin = round(duration/60,0)
| chart values(durationMin) by host
The search return - msg from different host/source got grouped together.
Is there a way to restrict transaction events only on same host/source?