<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to find the duration for order submission to each suborder process. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431766#M123409</link>
    <description>&lt;P&gt;@niketnilay  when i submit order the log looks like below.&lt;/P&gt;

&lt;P&gt;2019-08-05 21:27:20,311 INFO  Source=RESPONSE,ReqId=15686047,RequestId=bc50733f-c73e-4ea1-87f2-735a4c761a0e,OrderNumber=10169550&lt;/P&gt;

&lt;P&gt;after request processed, we can see individual sub line (sub order )details as below&lt;/P&gt;

&lt;P&gt;2019-08-05 21:27:32,354 INFO  {193}  AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=5,Status=Success&lt;BR /&gt;
2019-08-05 21:29:32,354 INFO  {193}  AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=1,Status=Success&lt;BR /&gt;
2019-08-05 21:27:42,354 INFO  {193}  AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=2,Status=Success&lt;BR /&gt;
2019-08-05 21:28:32,354 INFO  {193}  AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=3,Status=Success&lt;BR /&gt;
2019-08-05 21:27:12,354 INFO  {193}  AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=4,Status=Fail&lt;/P&gt;

&lt;P&gt;When i use this query all possible events are forming as one event.&lt;BR /&gt;
(source="source2" Source=RESPONSE)  OR (sourcetype="source1" AuditLog: A=CR) | transaction OrderNumber  duration&lt;/P&gt;

&lt;P&gt;i need to know time difference between main line to each sub line processing duration.&lt;/P&gt;</description>
    <pubDate>Mon, 05 Aug 2019 22:21:45 GMT</pubDate>
    <dc:creator>ravi08402</dc:creator>
    <dc:date>2019-08-05T22:21:45Z</dc:date>
    <item>
      <title>How to find the duration for order submission to each suborder process.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431764#M123407</link>
      <description>&lt;P&gt;I am working for a product where I will have one order number, it has multiple suborders.&lt;BR /&gt;
Once each suborder processes, I will get the suborder number and main order number. &lt;BR /&gt;
I need to find the duration for order submission to each suborder process.&lt;/P&gt;

&lt;P&gt;For example:&lt;BR /&gt;
&lt;STRONG&gt;my order is abc, sub orders i have 1,2,3&lt;BR /&gt;
my result set should be&lt;BR /&gt;
order  sub order     duration&lt;BR /&gt;
abc        1                      10&lt;BR /&gt;
abc         2                      23&lt;BR /&gt;
abc        3                       15&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;When I use transaction for this search I am getting duration between main order submission to last sub order processed.&lt;BR /&gt;
How do I get individual duration?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 23:36:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431764#M123407</guid>
      <dc:creator>ravi08402</dc:creator>
      <dc:date>2019-08-02T23:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the duration for order submission to each suborder process.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431765#M123408</link>
      <description>&lt;P&gt;@ravi08402 please add more details to the events from your sub order that help you identify that Sub Order is being processed and processing has completed. Also is there a state in the main order that identifies it starting and completion?&lt;/P&gt;

&lt;P&gt;What is the current transaction command you are using.&lt;/P&gt;

&lt;P&gt;Please ensure to mock/anonymize any sensitive information in your data/code before posting on Splunk Answers.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Aug 2019 02:53:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431765#M123408</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2019-08-03T02:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the duration for order submission to each suborder process.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431766#M123409</link>
      <description>&lt;P&gt;@niketnilay  when i submit order the log looks like below.&lt;/P&gt;

&lt;P&gt;2019-08-05 21:27:20,311 INFO  Source=RESPONSE,ReqId=15686047,RequestId=bc50733f-c73e-4ea1-87f2-735a4c761a0e,OrderNumber=10169550&lt;/P&gt;

&lt;P&gt;after request processed, we can see individual sub line (sub order )details as below&lt;/P&gt;

&lt;P&gt;2019-08-05 21:27:32,354 INFO  {193}  AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=5,Status=Success&lt;BR /&gt;
2019-08-05 21:29:32,354 INFO  {193}  AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=1,Status=Success&lt;BR /&gt;
2019-08-05 21:27:42,354 INFO  {193}  AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=2,Status=Success&lt;BR /&gt;
2019-08-05 21:28:32,354 INFO  {193}  AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=3,Status=Success&lt;BR /&gt;
2019-08-05 21:27:12,354 INFO  {193}  AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=4,Status=Fail&lt;/P&gt;

&lt;P&gt;When i use this query all possible events are forming as one event.&lt;BR /&gt;
(source="source2" Source=RESPONSE)  OR (sourcetype="source1" AuditLog: A=CR) | transaction OrderNumber  duration&lt;/P&gt;

&lt;P&gt;i need to know time difference between main line to each sub line processing duration.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 22:21:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431766#M123409</guid>
      <dc:creator>ravi08402</dc:creator>
      <dc:date>2019-08-05T22:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the duration for order submission to each suborder process.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431767#M123410</link>
      <description>&lt;P&gt;are the timestamps in your example data correct?&lt;BR /&gt;
is there a relation between LineSeqNumber and timestamp?&lt;BR /&gt;
Is it safe to assume the order happens before the sub orders? (its not the case in your example data)&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 23:50:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431767#M123410</guid>
      <dc:creator>diogofgm</dc:creator>
      <dc:date>2019-08-05T23:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the duration for order submission to each suborder process.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431768#M123411</link>
      <description>&lt;P&gt;2019-08-05 21:26:20,311 INFO Source=RESPONSE,ReqId=15686047,RequestId=bc50733f-c73e-4ea1-87f2-735a4c761a0e,OrderNumber=10169550&lt;/P&gt;

&lt;P&gt;after request processed, we can see individual sub line (sub order )details as below&lt;/P&gt;

&lt;P&gt;2019-08-05 21:27:32,354 INFO {193} AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=5,Status=Success&lt;BR /&gt;
2019-08-05 21:29:32,354 INFO {193} AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=1,Status=Success&lt;BR /&gt;
2019-08-05 21:27:42,354 INFO {193} AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=2,Status=Success&lt;BR /&gt;
2019-08-05 21:28:32,354 INFO {193} AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=3,Status=Success&lt;BR /&gt;
2019-08-05 21:27:12,354 INFO {193} AuditLog:A=CR,OrderNumber=10169550,LineSeqNumber=4,Status=Fail&lt;/P&gt;

&lt;P&gt;corrected the timestamp. No there is no relation between time stamp and LineSeqNumber.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2019 23:58:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431768#M123411</guid>
      <dc:creator>ravi08402</dc:creator>
      <dc:date>2019-08-05T23:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the duration for order submission to each suborder process.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431769#M123412</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Try this:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(sourcetype="source1" AuditLog: A=CR) 
| join OrderNumber [search (source="source2" Source=RESPONSE) | stats min(_time) AS start by OrderNumber]
| eval duration = _time - start
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Explanation:&lt;/STRONG&gt;&lt;BR /&gt;
sub search to get the time for each order number and the join the result using the order number in the sub order events making the order time available in every sub order. from there you can just calcule the duration using eval.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2019 00:15:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431769#M123412</guid>
      <dc:creator>diogofgm</dc:creator>
      <dc:date>2019-08-06T00:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to find the duration for order submission to each suborder process.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431770#M123413</link>
      <description>&lt;P&gt;Thanks it worked for me&lt;/P&gt;</description>
      <pubDate>Fri, 09 Aug 2019 21:53:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-find-the-duration-for-order-submission-to-each-suborder/m-p/431770#M123413</guid>
      <dc:creator>ravi08402</dc:creator>
      <dc:date>2019-08-09T21:53:19Z</dc:date>
    </item>
  </channel>
</rss>

