i have the 2 values let's say
expected time= 6:00:00
completion time= 08:32:44
and the expected output should be the difference of the above i.e (expected-completion) in 12 hrs format including negative sign for example : output= -2:32:44 (which is the diff between expected and completion)
Convert both times to epoch times (if they aren't already) using strptime()
Then subtract one from the other as diff (for example).
Then use tostring to display as hours:minutes:seconds
| eval x=if(diff<0,"-","").tostring(abs(diff),"duration")
Thanks @ITWhisperer it worked!