Query checking difference of two terms in a log

Wrong forum :slight_smile:

I found this in the logstash forum that looks relevant: Logstash Ruby filter to subtract difference between two timestamps in single event

1 Like