We need to use as the event timestamp the EndTime of the event but the EndTime is a calculated field from 2 other actual fields: StartTime + DeltaTime. Is this possible?
Hm. Well if you want the events to get indexed with that timestamp, i dont think it can be done. but someone else might know of a way.
If On the other hand, the _time as indexed today is close enough, but you just want to use this other more accurate value when you run reports, then you can modify the _time field itself.
| eval _time = StartTime + DeltaTime | timechart count
Of course, if the indexed _time value is off by enough to push it outside of the search timerange, then it wont show up in the report at all.