I've this specific requirement for log search when matching a keyword, the result show display the matched event and 5 lines before and after the matched event.
The search is simple as below:
index="booking" host=* "CreateBookingError"| table _raw
The objective is to know the chronological of events matching this keyword. How can I achieve it?
Have you tried this:
Hope it helps