is it possible in kibana scripted fields to compare data from multiple rows.
I have two search results
1. message = "abs" timestamp="hh.mm.ss" source="xyz"
2. message = "bsa" timestamp="hh.mm.ss" source="xyz"
source
is same but different messages and difference timestamps. i would like to show the timestamp difference
between these two timestamps when these messages were generated.
i have tried using painless scripting language but not sure how can i merge inputs from multiple rows.
I have multiple use cases similar to this where i have fetch data from multiple rows and do some logical operations and finally show the status like "Pass" or "fail" on each row. Please help.
These fields have to be later shown on visualizations.