Hi,
I need to find the transaction time between these 2 statements which has same startswith Log strings(different endswith) and hence its ignoring the first event.
2014-07-04 09:48:00-System Up - Node1 is down
2014-07-04 09:43:00-System Up
How could I find the transaction time between these 2 events.
My suggestion would be to create a field called message which will store the message after "System Up -", so that it would be blank/null for 2nd event and you can use that as startswith (different in both entries).
something like this
Your base search | rex "System Up\s*-\s*(?<message>.*)$" | transaction startswith="System Up AND NOT message=*" endswith="System Up message=*"