I have one machine it displays values zero and one . if its value is zero for one hour i want that from time and to time of that machine.
Hi ajayabburi508
let me better understand:
do you want a search that when for an hour you have only value=0 and not value=1, it displays from_time and to_time?
if this is your need run an alert like this every five minutes:
index=your_index sourcetype=your_sourcetype
| transaction maxspan=1h
| search value!=1
| stats earliest(_time) AS earliest latest(_time) AS latest
Bye.
Giuseppe