Is there such thing to display a minspan for transaction...
Trying to looking for users from building A to Building B... but getting junk events from trnasaction with a duration of a couple of seconds...
Is there a way to set min span? as i have the maxspan for currently 10mins
| transaction User startswith=location="A" endswith=location="b" maxspan=10m
You could follow it with the following to only keep transactions lasting more than 60 seconds between the first and last event in the transaction:
| where duration > 60