I have logs which contain a log line for starting and finishing a process. it looks like this:
I need the time difference between the "tux state retrieved" and "tux state retrieved". Since the data is already indexed, I would like to know, if there is an option to calculate this in kibana or timelion as postprocessing.
I am aware that there are possibilities of calculating it on index times in logstash. I will check this in future.