Since I couldn't find this anywhere, I'm making my own question and answer, to better help the "next guy" who has this question and can't find the answer either.
I wanted a simple query of an error condition in our email logs, then return the grouped log events associated with that exchange. Since email logs are line by line (multiple events) their only connection is the MID.
Answer below:
index=main [ search index=main (host=esa1* OR host=esa2*) "possible delivery" | stats count by MID | fields + MID | format] | transaction MID
This will search for the error "possible delivery" on a line, then use the MID field to pivot from and collect all the line events from that exchange.
index=main [ search index=main (host=esa1* OR host=esa2*) "possible delivery" | stats count by MID | fields + MID | format] | transaction MID
This will search for the error "possible delivery" on a line, then use the MID field to pivot from and collect all the line events from that exchange.