I am using the transaction command, but the events are not collated when they took place at the same time and directory
eventtype=ossec integrity HKEY NOT tag::eventtype=noise | transaction reporting_host,file_dirname
It looks like you have bad line-breaking.. If this is the case, then you should fix it at the index level compared to using a transaction command at the search level to maximize performance. Is the current line-breaking correct?