Hi everybody ...
i have these kind of logs in my environment. every transaction has these 4 log messages but there is no unique id for every transaction. simply it's generating this kind of message, but there is no information to correlate this information for 1 particular transaction. but i need to find the INFORMATION whatever in between inbound and outbound. can anyone help me in that?
Thanks in advance.![alt text][1]
Give this a try. This should group relevant transaction events together.
Your base search | eval transfield=if(searchmatch("Outbound Message"),1,0) | accum transfield | transaction transfield
If you're looking for specific output, please provide a sample/details of that.