Hi , I am creating a dashboard where it should show the time difference between two latest events, since all the events look alike, I do not want splunk to pickup the old events timestamps and compare with the new one. I tried using dedup and it is showing only for one particular day even though I selected a range of dates. Query: index=i01_prd ("ProcessBatch" AND "Total Processed") OR (ProcessBatch BEGIN - ProcessBatch.doWork) | bucket _time span=1d as day | stats earliest(_time) as First latest(_time) as Last by day | eval DurationInMinutesDeci=round((Last - First)) | eval day=strftime(day,"%m/%d/%y") | eval Last=strftime(Last,"%S") | eval First=strftime(First,"%S") | rename Last as "Last_ss" | rename First as "First_ss" | rename DurationInMinutesDeci as Seconds | rename _time as exacttime | rename day as _time | table _time, Seconds
... View more