I have created an alert which basically checks the occurrence in particular keyword in two log files , however there is a difference of time from anywhere between 1 min to 1 hours for that keyword to appear in both log files.
Example:-
If keywork CorrID appears in Log File A, then it can appear in Log File B between anywhere from 1min to 1 hour.... So our search first checks in Log File A and then wait for an hour to check in Log File B.
Problem is when keyword does not appear in Log File B for more than 1 hour, then we get an alert, which is false, because keyword had appeared up in Log File B after 70 minutes.
So now, I want to run a search which verifies the output again in last two hours in both log files..?
... View more