Hi, I have some issue with transaction command. It works fine. but sometimes endswith pattern appear and startswith pattern in the log. So the transcation command failing to convert that as a transaction.
For example,
Works fine for below log,
XXXXXXXXXend
XXXXXXXXXstart
Occassionally the data reverses like below and trasnaction command doesnt find it
XXXXXXXXXstart
XXXXXXXXXend
Is there a wrok around for this?
Hello @graju89,
I haven't any good solution for you, so may be just use an ineffective way of appending two searches:
search ... |transaction startswith="start" endswith="end" maxspan=10s|sort 0 - _time| fields action duration | append [search ... |transaction startswith="end" endswith="start" maxspan=10s]