How to get the timestamp difference

Hi All

I am trying to get timestamp difference for the following kql filter

Here log_message and timestamp are fields

Screenshot attached

log_message : "submit async job-514" or log_message : "Complete async job-514"

The filter throws two documents having different timestamp field values.

Do I need to use scripted fields, vega, timelion to get the difference

Any help on this would be helpful

Any help on this

Welcome to our community! :smiley:

This has been asked before numerous times, I would suggest doing a quick search for existing topics :slight_smile:

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.