Hello All,
Never mind. figured out. the below one worked. thank you
| eval time=_time | eval indextime=_indextime | eval diff=time-indextime | where diff>=0 | convert ctime(indextime) | convert ctime(time) | table time indextime diff
What was it that you would like that isn't covered by using _indextime?
Never mind. figured out. the below one worked. thank you
| eval time=_time | eval indextime=_indextime | eval diff=time-indextime | where diff>=0 | convert ctime(indextime) | convert ctime(time) | table time indextime diff