I've got a search problem that I've been trying to solve with some combination of transactions and events.
Hi all. I am trying search for a specific incident in one of our sources. The characteristics of the incident are:
Example:
hostA log2 event 1
hostA log2 event 2
hostA log2 event A
hostA log2 event B
hostA log2 event 1
hostA log2 event 2
Any suggestions on the best way to capture these incidents?
As I said, I have tried transactions, events and eventtypes, with no luck so far.
Thanks in advance for any advice.
I would try the general approach of:
This is an interesting problem, can you describe what the real-world incident is with these events?