I'm creating a transaction that is displayed in the following table:
table _time,src_ip,accountname,username,attack,duration,eventcount
The attach field is multivalued. If I just pipe the transaction command to a table, they are displayed in alphabetical order. If I use rex to extract the desired field from the event, it's displayed in the order that the events occurred.
Is it possible to make those values appear chronologically without using rex?
Thx.
C
yep! just figured it out the other day
... | transaction mvlist=t ...
Reference: http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transaction
Yes that is it. Worked for me to.