Hi All
I am trying to get timestamp difference for the following kql filter
Here log_message and timestamp are fields
Screenshot attached
log_message : "submit async job-514" or log_message : "Complete async job-514"
The filter throws two documents having different timestamp field values.
Do I need to use scripted fields, vega, timelion to get the difference
Any help on this would be helpful