The **transaction** command groups multiple events into a single logical event based on common fields (like a session ID).
You can define the boundaries of a transaction using `startswith` and `endswith` strings, or physical time constraints like `maxspan` (maximum total duration) and `maxpause` (max gap between events).
index=web | transaction session_id startswith="login" endswith="logout" maxspan=2h