I want to get the duration of the session from start to completion but also need to session number. I set up my search with a transaction starting with the "Choose" event and ending with the "Session complete" event in order to get the session number with the grouping, but I need to access the "Start session" event to calculate the duration. How should I go about this? My search is below:
index=INDEX host=HOST sourcetype=SOURCETYPE earliest=-1d@d latest=now | rex field=_raw "UserId:(?<user_id>\d+)\sSession\scomplete" | rex field=_raw "UserId:(?<user_id>\d+)\sStart\ssession" | rex field=_raw "UserId:(?<user_id>\d+)\sChoose\slocation\sfor\ssession:(?<session_id>\d+)" | where user_id<3000 | sort 0 user_id -_time | transaction user_id startswith="Choose" endswith="complete"