Hi all, i have a query for transaction,
source="abc_data1_*" index="testing" sourcetype="_json" | transaction startswith=(STATUS="FAIL") endswith=(STATUS="SUCCESS")
The events in the results are considered from most recent to oldest. But i want this transaction to consider the the older data first to the processing. I want the data to be sorted from the beginning and then apply the transaction. "Reverse" doesn't work with this.Anyone knows how to do this?
Have you tried Tail ?
| sort 0 _time
Hi sir, I am getting the events like this. only one event is older and the rest is new data.
As you can see only first event is older.
What is your full search?
source="abc_data1_*" index="testing" sourcetype="_json" | transaction startswith=(STATUS="FAIL") endswith=(STATUS="SUCCESS")
This is only my full search.
8/4/21 is not older than 7/30/21
Can you share some of your raw events as it doesn't look like your transaction command is working.