I am new to Elastic Search and Kibana Query Language.
I would like to find the time difference between the two documents which have the id as common between them as like below.
TimeStamp TRACE ID
2021-03-29 20:45:15.748 START 1234
2021-03-29 20:46:15.148 END 1234
I have given my tries with SQL Join and LAG and LEAD functions. But unfortunately, ES Driver doesn't support these as of now.
It would be really helpful if someone can help with either SQL or other search mechanisms in ELK.