How do I get all the individual event times from a transaction and have them in a multivalue field as part of the transaction?
Easy way to do this is just assign _time to another variable before the transaction. In the following example, I've also used strftime to convert from epoch to human-readable format:
sourcetype=foo "your search here" | eval times=strftime(_time,"%F %H:%M:%S") | transaction bar
Now times will be a multivalue field that contains all the individual timestamps from each event!
View solution in original post