I am grouping the data by using transaction (using maxspan option).
After that the requirement (final result) is to pick the first element from each group and display. How can i do that??
Hi,
Sorry need a little clarification; what do you mean by first element from each group?
The transaction is just going to group the events in a different sequence or by a particular field; after that transaction you still need to use some function to report on your results (stats/table/timechart).
You can however display your results by using a | top <field> limit=1
command if you only want to see the most common value from that field.
-Kate