Just twisting @vnravikumar 's answer.
@manurajrajappan
Can you please try this?
YOUR_SEARCH | eval diff = strptime(Previous_Time, "%Y-%m-%dT%H:%M:%S.%9N%Z") -strptime(New_Time, "%Y-%m-%dT%H:%M:%S.%9N%Z")
| where diff >3
| fieldformat diff = tostring(diff, "duration")
| table New_Time, Previous_Time, diff
Sample:
| makeresults
| eval New_Time="2020-01-22T03:17:36.385000000Z",Previous_Time="2020-01-22T03:17:39.388208200Z"
| rename comment as "Upto this is for data generation only"
| eval diff = strptime(Previous_Time, "%Y-%m-%dT%H:%M:%S.%9N%Z") -strptime(New_Time, "%Y-%m-%dT%H:%M:%S.%9N%Z")
| where diff >3
| fieldformat diff = tostring(diff, "duration")
| table New_Time, Previous_Time, diff
... View more