I didn’t say by hostname in eventstats
remove by hostname in eventstats
If there are only two rows then you can use range. Add below search to your search.
| eventstats range(EventCount) as diff_event_count
| where diff_event_count=15
@thambisetty I will definitely like it 😃 if you can help with the request
The main request erased, I'm sorry, all the same data.
The request itself for the last hour was supposed to show by example the difference in events of 5 pieces. I took 5 as an example.
In your version, I did not find this difference in 5 pieces.