All,
Is it possible to assign your appended search a separate color so it's easier to spot appended events in the timeline view?
eventtype=opsec_drop 127.0.0.1 tcp_flags="PUSH-ACK" | append [search sourcetype=access_combined source="/var/log/httpd/example_*"]
The thought is that it would allow us to quickly narrow down exactly where two events occurred.
Thanks
Define eventtypes for each, do one search (no subsearch append stuff) like this:
eventtype=type_one OR eventtype=type_two
and configure your two eventtypes with different colours.
The colours appear in the displayed raw events.
Thanks, to be clear this is to customize the timeline display during a search correct?