I've anonymised an SET and UPDATE event which you can see below. To find the related events I'm using the field "AlarmID". Unfortunately, I'm not really having an idea how to properly do it, so I don't have any search for that particular request but I'll past the search I'm using to get duration till clear. Thanks a lot Event Example This is the UPDATE Event ============================================================ Current Date and Time is : Mon Jul 5 17:47:31 CEST 2021 Alarm Notification from XXXXXXXXXX Alarm UPDATEd: UpdateDate: 07/05/2021 UpdateTime: 17:47:31 DeviceType: XXXXXXXXXXX Mtype: XXXXXXXX ModelName: XXXXXXXXXX AlarmID: 6755882 AlarmTitle: Issue with Network Device TTID: INCXXXXXXXX GlobalAlarmID: 12345678-12345678-12344566 Severity: CRITICAL ProbableCauseID: 10009 RepairPerson: AlarmStatus: XXXXXXXXX IPAddress: xx.xx.xx.xx AlarmState: NEW Acknowledged: FALSE UserClearable: FALSE Location: AlarmAge: 0 NotificationData: ProbableCause: Issue with Network Device IfName: XXXXXXXXX IfDesc: XXXXXXXXX IfAlias: XXXXXXXXXX TicketStatus: XXXXXXXXXX CRQ_ID: Maintenance: EnrichmentInfo: Processing_time_00:06:04 ============================================================ This is the SET event ============================================================ Current Date and Time is : Mon Jul 5 17:38:28 CEST 2021 Alarm Notification from XXXXXXXX Alarm SET: SetDate: 07/05/2021 SetTime: 17:38:27 DeviceType: XXXXXXXXXXX Mtype: XXXXXXXXXXX ModelName: XXXXXXXXXXX AlarmID: 6755882 AlarmTitle: Issue with Network Device TTID: GlobalAlarmID: 12345678-12345678-12344566 Severity: CRITICAL ProbableCauseID: 10009 RepairPerson: AlarmStatus: IPAddress: XXXXXXXXXXX AlarmState: NEW Acknowledged: FALSE UserClearable: FALSE Location: AlarmAge: 0 NotificationData: ProbableCause: Issue with Network Device IfName: XXXXXXXXXXX IfDesc: XXXXXXXXXXX IfAlias: XXXXXXXXXXX TicketStatus: CRQ_ID: Maintenance: EnrichmentInfo: ============================================================ Search I'm using for the Clear Case (thats already a drilldown search from a bar chart in which a counting of alarms cleared in a bucket is presented) index=general sourcetype=alarming (Event_Type=SET OR Event_Type=CLEARER)
| transaction AlarmID startswith=Event_Type=SET endswith=Event_Type=CLEARED
| eval duration_bucket=case(duration<=10, "0-10sec", duration=0, "0sec", duration>10 AND duration<=30, "10-30sec", duration>30 AND duration<=60, "30-60sec", duration>60 AND duration<=120, "60-120sec", duration>120 AND duration<=180, "120-180sec", duration>180 AND duration<=240, "180-240sec", duration>240 AND duration<=300, "240-300sec", duration>300, ">300sec")
| search duration_bucket=180-240sec
| table _time, DeviceName, AlarmTitle, duration
... View more