I made the following search to group exceptions together that happened within 1 second but I want to be able to view the source and make the search more efficient. Is there a search that will yield the same results without using the transaction command?
index=java_logs Exception | transaction maxspan=1s
Yes, try this:
index=java_logs Exception | bin _time span=1s | stats list(_raw) AS events values(source) AS sources BY _time
Yes, try this:
index=java_logs Exception | bin _time span=1s | stats list(_raw) AS events values(source) AS sources BY _time
Try index=java_logs Exception | bin span=1s _time | stats values(*) as * by _time