Is there an equivalent of a reverse transaction search command that would look backwards in time for events when a certain event occurs? For example, adding a Cisco switch port to a particular vlan looks like:
switchport access vlan 100
We can't tell what port that command was accessed on unless we can capture the last X events from that user on that host. Is that possible?
There are two ways that strike me, you could do this. As I imagine you already considered, you could try to configure transactions to do a startswith=interface endswidth="switchport access" but that may be too brittle for your needs. The other avenue I'd go down is with localize. See if these can do what you're looking for: