Hi all, i have a query for transaction,
source="abc_data1_*" index="testing" sourcetype="_json" | transaction startswith=(STATUS="FAIL") endswith=(STATUS="SUCCESS")
The events in the results are considered from most recent to oldest. But i want this transaction to consider the the older data first to the processing. I want the data to be sorted from the beginning and then apply the transaction. "Reverse" doesn't work with this.Anyone knows how to do this?