I'm trying to correlate the eventcode 1234 in index1 with errors that show up in index2
I need help capturing the "host names" which are the same in both indexes so I can correlate exactly. The problem is that index2 throws this particular error text, but it's generally not a problem unless it occurs around eventcode 1234
Hello! First a question. How do you use your starttimeu=$starttime$ endtimeu=$endtime$?
I think, for it to work, you must have something like this bellow, with starttime and endtime as fields in your index1 events:
And, starttimeu and endtimeu must be fields int your index2 events, and must respectively have same values with starttime and endtime. If that is not the case, remove that starttimeu=$starttime$ endtimeu=$endtime$ in your code.
Ok. To capture the host names, that is what you can do.