Hi,
Is it at all possible for the aggregate filter to have the timeout according to a timestamp field in the event itself rather than the system time?
This is important for me because I want to index some old logs and I want the aggregation to be done by the original timestamp.
Thanks for your help!