So I have a log with multiple VPN connection, and some of them reconnect to the same session multiple times a day for example:
08:02:00- User A login
08:10:12- User A login, replace old connection
08:12:13- User A login, replace old connection
08:15:13- User A logout, disconnected
when I use transaction , splunk only get the events at 08:15:13 and 08:12:13 , but I want it to get the earliest event at 08:02:00, are there any way to achieve that ?
Ignore the replace old connection
events in your startswith
condition.