Hi,
I would like to know if there is option to unify logs based on id or something else.
For example:
I have the initial log and after 15 sec, I get an update for that log (not necessarily sequential).
Is there any option to merge them into 1 log (instead of 2) and doing it before indexing (since I want to index 1 log)?
Thanks,
Shay
Hi,
You can do that with transaction
command. Also refer documents for it:
https://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/Transaction