I got my query result in another way but its partial. Here I use below query. search A | eval Date=strftime(_time, "%d/%m/%Y") | stats latest(_time) AS Latest by Date | eval Endtime_mail=strftime(Latest,"%Y/%m/%d %H:%M:%S") | join Date [search search B | eval Date=strftime(_time, "%d/%m/%Y") | stats earliest(_time) AS Earliest by Date | eval starttime_mail=strftime(Earliest,"%Y/%m/%d %H:%M:%S") ] | table starttime_mail,Endtime_mail Now I am not able get date-time difference between starttime_mail and Endtime_mail. Difference should be like 1 day ,3 hour, 43 minute.
... View more