query like below:
| transaction startswith="Init" endswith="FINISHED" by ip
| table duration ip
Each IP has multiple "init" and "finish". Is there a way to group the first "init" to the last "Finished" instead of grouping the closest two?
Thanks in advance!
"your search" "init" OR "finished" |stats earliest(_time) as first,latest(_time) as last by ip|eval duration=last-first
View solution in original post
it works, thank you very much! much appreciated!