I have three indexes that I'm trying to build a transaction from. the first two indexes each have a field named User_Name, which makes the transaction statement pretty easy. This creates the base transaction I'm looking for.
The first index also has a field called ip. What I want to do is use this field to retrieve the events from the third index into the first transaction (unfortunately the User_Name field does not exist in the third index). I've tried so many different searches, all never result in a transaction containing all the pertinent records.
Any thoughts on how to create this type of transaction?
asked 25 Mar '11, 02:36
I am also keen to see what the data looks like as mentioned by southeringtonp. Have you thought about doing data enrichment using a lookup of some unique data and then using the new field to transact on.
answered 07 Apr '11, 15:00
Maybe this isn't the best place to ask this question but I'll try anyway.
Can I transaction span multiple indexes and multiple sourcetypes? It seems like it can but I thought I would ask to verify it.
answered 28 Sep '11, 12:47