I don't think I am understanding the question. Each process has a start and end and your script was able to capture them for one time period. How does Splunk handle moving through time and recording the next instance of the event pair? A series of occurrences of an event can be charted by time, I thought the only difference in this query is that the series of occurrences is a pair of events. I apologize if I am not understanding you clearly. I do appreciate your time and assistance.
... View more