I am doing log analytics to debug an issue where few of our devices are randomly going for reboot. I have the uptime parameter which tell me when the device rebooted. I want to find any interesting event that occurs prior to any reboot. I suppose I can use "Significant Terms Aggregation" here. For that, I would like to create a foreground set that filters events to "All Log messages X minutes prior to the reboot event". I can then apply Significant Term on actual Log message. Is this the right approach? If so, how can I write the above query?