in my logs the "connectionid" on one _raw log and the fcid
I tried this
sourcetype=foo | rename connectionid AS transactionid fcid AS transactionid | transaction transactionid
and it seems to work but there has to be a better way.
Similar one
sourcetype=foo | eval transactionid=coalesce(connectionid , fcid)| transaction transactionid
Somesoni,
Thanks for the suggestion. Can you put this in as an answer so I can give you credit
Similar one
sourcetype=foo | eval transactionid=coalesce(connectionid , fcid)| transaction transactionid