@ schiggy
Можете ли вы попробовать это?
YOUR_SEARCH | transaction startswith="variableX=1" endswith="variableX=0"
| table _time duration
| stats sum(duration) as total_duration
Мой пример поиска:
| makeresults count=10
| eval diff=10
| accum diff
| eval variableX=if(diff%20==0,0,1)
| eval _time=now()-diff
| table _time variableX
| transaction startswith="variableX=1" endswith="variableX=0"
| table _time duration
| stats sum(duration) as total_duration
| eval total_duration=tostring(total_duration, "duration")