Should something like this work?
doc['timestamp'].value - doc['data.LOGON_TIME'].value;
I've tried numerous variations. Setting variables. using a return statement.
I basically just need to know how many milliseconds or seconds between these 2 fields.
I get this message in Discover:
Courier Fetch: 5 of 25 shards failed.