Splunk replaces rising column itself, you need not specify it explicitly in the query. Try below.
SELECT DISTINCT PRQ.RPT_QUEUE_ID, LRF.FORM_DESC,CU.USER_FULLNAME AS "Scheduled_By", PRQ.SCHEDULED_ON, PRQ.EXECUTION_DATE, MAX(PRS.TOTAL) AS "Total_Case_Count" , ROUND((MAX(PRS.END_DATE) - MIN(PRS.START_DATE)) * 3600,2) AS "Run_Time_in_Sec" FROM ARGUS_APP.PER_RPT_QUEUE PRQ, ARGUS_APP.PER_RPT_STATUS PRS, ARGUS_APP.LM_REPORT_FORMS LRF, ARGUS_APP.CFG_USERS CU {{ WHERE $rising_column$ > ?}}
And specify your rising column in the field provided below the SQL query "Rising Column*"
... View more