Hello everyone.
Want to display the output only for the time which crosses 18 months (earliest time)
You would need to compare against epoc. One way to check would be
|tstats `summariesonly` earliest(_time) AS et where index=* by index, sourcetype, _time span=1mon | where > 1546300800
I have used the epoc time converter to get 154* dating back to 18months. you can change as needed
I may not have understood your question fully, however this query will show you all sourcetypes for which your earliest event is older than 18 months.
|metadata type=sourcetypes|eval 18months=now()-84600*548|search firstTime<18months