Hi Martin
Thanks, I was looking at the option of using the summary index, running the "transaction sessionid" every 1 minute, however, I have seen that there are many log with sessionid outside the window of 1 minute. That is, for example:
Aug 18 21:22:02 172.24.20.35|sessionid:f79a66d0000002d5-cf-53f2b45b0526|EHLO|mail.netsol.com
Aug 18 21:22:02 172.24.20.35|sessionid:f79a66d0000002d5-cf-53f2b45b0526|MSG_SIZE|56702
--------------------- end window 1 minute---------------------------------------------
Aug 18 21:21:47 172.24.20.35|sessionid:f79a66d0000002d5-cf-53f2b45b0526|MSGID|35845b9268841243
Aug 18 21:21:31 172.24.20.35|sessionid:f79a66d0000002d5-cf-53f2b45b0526|SUBJECT| rv: informe
Aug 18 21:21:05 172.24.20.35|sessionid:f79a66d0000002d5-cf-53f2b45b0526|SOURCE|external
Aug 18 21:21:03 172.24.20.35|sessionid:f79a66d0000002d5-cf-53f2b45b0526|SENDER|
[email protected]
--------------------- start window 1 minute---------------------------------------------
Aug 18 21:20:52 172.24.20.35|sessionid:f79a66d0000002d5-cf-53f2b45b0526|CLIENT|209.17.115.10
And when I look at the summary index, there are many events with incomplete fields.
Have you ever touched this case? maybe I can improve the search transaction
... View more