I have several different source types and I need to create a report on them, most of them have events with all the fields I need, but one of them doesn't because the events are broken into other events that can become a transaction.
When I pipe only those events to the transaction command I get all the fields I need, but I don't know how to incorporate the results with the other searches that don't require a transaction.
This is the search for my normal report:
index=* sourcetype=a sourcetype=b | table file_name, action, user
And this is the search I have to incorporate into the report:
index=* sourcetype=c | transaction id| table file_name, action, user