index=main source=secure.log sourcetype=*
| stats earliest(_time) as start, latest(_time) as stop
| eval start=strftime(start, "%m/%d/%y") | eval stop=strftime(stop, "%m/%d/%y") | eval days = round((start-stop)/86400). Please refer my below result.
start stop
11/16/18 11/23/18
Here i can see start and stop date but want to find difference between start and stop so i can found number of days gap between them. So in above result i wants days column and difference is 7 days. But days column is not coming here. Please suggest.
try below-
| eval start = strptime(start , "%m/%d/%y")| eval stop = strptime(stop, "%m/%d/%y")| eval days= round((stop-start)/86400)