Hi All,
I got out put like this
From date Todate
03/02/2018 09:41:26 03/02/2018 12:55:52
03/02/2018 12:55:53 03/02/2018 14:00:00
But there is no -difference which is in Bold so I want output like this
From date Todate
03/02/2018 09:41:26 03/02/2018 14:00:00
have a look at transaction command:
https://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/Transaction