Hello,
I'm using a transaction command and what I want to do is find the next event that has the format "{DATE} INFO"
and then use the event previous to the found event.
Any ideas?
For example, endswith="{SEARCH}-1"
I have found a solution.
The solution I encountered is to create a new sourcetype and use the "SHOULD_LINEMERGE" boolean attribute with the property of BREAK_ONLY_BEFORE set with the regex of where the new statements should start.
Hope this helps
I have found a solution.
The solution I encountered is to create a new sourcetype and use the "SHOULD_LINEMERGE" boolean attribute with the property of BREAK_ONLY_BEFORE set with the regex of where the new statements should start.
Hope this helps