Currenty search results are sorted descending according to Event Time. But when two same events have the Event Time parameter same, the order of these events is wrong. This is common for correlated events. Search results with them looks like the correlation event was earlier than raw event. It is also possible to see situations that user was logged off before he logged in and started working.
by: Jakub M. | over a year ago | Other
Comments
We are accepting this idea into our backlog. When it is planned for development, the status of the idea will be changed to "Planned".