In the above since logB indicates job run before logA completion time, it is an indication of the concurrent run of the process. I would like to generate a list of all such jobs if it is possible, any help is appreciated.
| stats earliest(_time) AS begin, latest(_time) AS end count by source
| sort 0 begin
| autoregress end as prev_end p=1
| where begin<prev_end
| convert ctime(begin), ctime(end)
| sort - count
If that doesn't give you what you want, then consider using streamstats to calculate the window
I am not sure of the relevance of count in your scenario.