Hello Everyone,
I want to find duration between the events in a transaction.
Let's say I have 100 events In a transaction, there is a failure at 49 th event and it is continued to 69th event so I want to calculate the difference between these two and find out how much time taken between these 20 events.
Can anyone of you help me on this?
for a transaction?
sorry, I don't use it.
your_search
| reverse
| streamstats count(searchmatch("failure"))) as session by your_transaction_id
| stats range(_time) as duration by your_transaciotn_id session
| eval duration=tostring(duration,"duration")