Dear @Richfez , First of all, I would like to thank you for the quick response ! I tried the above mentioned query and this came as the output : Seems to be working perfectly but one issue which I noticed is the time stamp. It gives time 2 hours back. I tried to create a query, which is not how I should have done it but it seems to give me the required output: earliest=-1h@h latest=now index=_internal blocked=true name IN (parsingqueue,typingqueue,aggqueue,indexqueue,auditqueue,exec) | stats count | append [ search earliest=-2h@h latest=-1h@h index=_internal blocked=true name IN (parsingqueue,typingqueue,aggqueue,indexqueue,auditqueue,exec) | stats count] | append [| makeresults | eval count=relative_time(now(), "@h") | convert timeformat="%m\%d\%y %l:%M.%S%p" ctime(count) | fields - _time] | transpose header_field=a | fields - column | rename "row 1" as "event1","row 2" as "event2", "row 3" as Time | eval Event_This_Hour=(tonumber(event1)) | eval Event_Last_Hour=(tonumber(event2)) | eval change=Event_This_Hour-Event_Last_Hour | rename change as "Change_In_Number_Of_Events" | table Time,Event_This_Hour,Event_Last_Hour,"Change_In_Number_Of_Events" If it is not much of a pain to you, I would like to request you to take a look at this and provide your valuable suggestions: Once again, thanks alot @Richfez !!!! Regards, Abhishek Singh
... View more