Hello, I'm trying to create a search that grabs an authentication failure event followed by a an authentication success event from the same src. My current search looks like this: index=wineventlog sourcetype=wineventlog source=wineventlog:security EventCode=4625 src=host1 | stats values(dest) as dest by _time, src | eval event_id=start | search [| search index=wineventlog sourcetype=wineventlog source=wineventlog:security EventCode=4624 src=host1 | stats values(dest) as dest by _time, src | eval event_id=finish] | transaction src startswith=event_id=start endswith=event_id=finish maxspan=2m | stats values(dest) as dest by _time, src Each individual search runs fine on it's own and finds events for host 1, and comparing the results of each search, I can see that the events occur within 2 minutes of each other. However my transaction search fails to grab both events. Instead it only grabs the events from the first search, and fails to grab the events from the sub search. Am I missing something?
... View more