I am using transaction and sending the result to an external workflow. The combined results from transaction appear one of the other which looks cluttered. Is there a way to make the individual events from transaction to appear as separate lines? I hope I am making sense.
Thanks.
There is a way you can do this with an eval function to insert a new line before the transaction. You will have to paste the new line in as typing it will trigger a search.
sourcetype=cisco_esa | eval _raw=_raw+"
"| transaction mid icid dcid
If you are adding this into a config file add a backslash \ before the newline.
This no longer works in v6.2.