@tread_splunk What if I wanted to add a column of the "Session_Start" epoch time as readable time. Maybe the table would be.. But for some reason, by doing this, it added more than one time. Any Ideas? | makeresults
| eval _raw="Host Account_Name Group Session_Start Session_End Duration
fdk-DC01 jim.smith logon 1611665560
fdk-DC01 jim.smith logoff 1611774585
fdk-DC01 jim.smith logon 1611665570
fdk-DC01 jim.smith logoff 1611774595"
| multikv forceheader=1
| table Time Host Account_Name Group Session_Start Session_End Duration
| eval Session_End=if(Group="logoff", Session_Start, null())
| eval Session_Start=if(Group="logoff", null(), Session_Start)
| eval Time = strftime(Session_Start, "%m/%d/%y %H:%M:%S")
| fields - Group
| stats values(*) as * by Host Account_Name
| eval StartEnd=mvzip(Session_Start,Session_End,":")
| mvexpand StartEnd
| rex field=StartEnd "(?<Session_Start>.*):(?<Session_End>.*)"
| eval Duration=tostring(Session_End - Session_Start, "duration")
... View more