From the looks of the screenshot it appears that event_time probably isn't in epoch format so the diff isn't being properly evaluated. How does it look when you try this? index=notable
| eva...
See more...
From the looks of the screenshot it appears that event_time probably isn't in epoch format so the diff isn't being properly evaluated. How does it look when you try this? index=notable
| eval
event_epoch=if(
NOT isnum(event_time),
strptime(event_time, "%m/%d/%Y %H:%M:%S"),
'event_time'
),
orig_epoch=if(
NOT isnum(orig_time),
strptime(orig_time, "%m/%d/%Y %H:%M:%S"),
'orig_time'
)
| eval
event_epoch_standardized=coalesce(event_epoch, orig_epoch),
diff_seconds='_time'-'event_epoch_standardized',
diff=tostring(diff_seconds, "duration")
| table _time, search_name, event_time, diff