I have the same requirement.
I need to calculate the average time for all the notables to get resolved over a 30 day period.
Can anyone help me with the splunk query regarding same?
We have different notable search and have alerts to trigger for same. I need to have query which shows when incident status changes to "in progress" and when to "resolve" and average ( consider for monthly ) time taken to resolve it.