|
I have a search defining a Transaction across (2) different log files. The problem is that some fields (not all) are missing in the results when using the transaction command. When I search for the events in the individual logs, the fields are present. Any ideas? These are all FIELD=VALUE. |
Are they still missing if you use |fields and specify that field? (I'd guess yes, but don't know.)
I am noticing this problem too. When I search for the first event in my transaction, I see 100% of them with the
destfield. When I transact them together with a few nearby log entries that do not havedestfields, ... SOME transactions havedest, some do not.