Not 100% sure I understand your question correctly, but I believe that you could use the
mvindex() function of
eval to specify the last element in the array (i.e. a multi-valued field).
Possibly you could also use the
max() function for
stats, if the
time field is numeric;
... | stats max(time) by sessionID
Also, if you have built
transactions based off the sessionID's, Splunk will automatically create a new field called
duration which may be good enough for you.
Hope this helps,