You can do something like this:
| tstats avg(_indextime) AS avg_indextime max(_indextime) AS max_indextime WHERE index=* BY sourcetype host _time
| stats avg(avg_indextime) AS avg_indextime max(max_indextime) AS max_indextime BY sourcetype host
| where ((avg_indextime > 30*60) OR (max_indextime > 30*60))
... View more