I have a transaction command which correlates two log entries. If I pipe this result into a timechart command, which log entry's timestamp does it use to bucketize the results (the first or the second)?
Also, is there a way to specify this?
Thanks! Jonathan
Hi Jonathan
The time stamp used is the one from the earliest event in the transaction. and I don't believe there is a way to change that.
Other option, depending on your use case, would be to use stats instead and then you could use min(_time) and max(_time) so you end up with 2 time fields that you can choose from.
The transaction will generate a duration field which you can add to _time to get the end time.
| transaction ........
| eval _time=_time+duration
| timechart ........