<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Transaction starts with ends with in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498914#M138975</link>
    <description>&lt;P&gt;Hi does anyone know is there is a way for transaction starts with ends with take the middle result Example, i have transaction DESCRIPTION startswith = VALUE = “RUN” endswith =VALUE=“STOP”&lt;/P&gt;

&lt;P&gt;In my data there is RUN,STOP,RUN,RUN,RUN,STOP,RUN,STOP,STOP,RUN,STOP.&lt;/P&gt;

&lt;P&gt;Apparently the Transaction command works with RUN,STOP but if there is RUN,RUN,RUN,STOP it will only take the last part of the RUN,STOP. &lt;/P&gt;

&lt;P&gt;Does anyone know a way it can get information from RUN,....,....,STOP , and also RUN,STOP,STOP it will get RUN,....,STOP&lt;/P&gt;

&lt;P&gt;I hope you all understand what i meant.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Mar 2020 03:11:24 GMT</pubDate>
    <dc:creator>chookp</dc:creator>
    <dc:date>2020-03-23T03:11:24Z</dc:date>
    <item>
      <title>Transaction starts with ends with</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498914#M138975</link>
      <description>&lt;P&gt;Hi does anyone know is there is a way for transaction starts with ends with take the middle result Example, i have transaction DESCRIPTION startswith = VALUE = “RUN” endswith =VALUE=“STOP”&lt;/P&gt;

&lt;P&gt;In my data there is RUN,STOP,RUN,RUN,RUN,STOP,RUN,STOP,STOP,RUN,STOP.&lt;/P&gt;

&lt;P&gt;Apparently the Transaction command works with RUN,STOP but if there is RUN,RUN,RUN,STOP it will only take the last part of the RUN,STOP. &lt;/P&gt;

&lt;P&gt;Does anyone know a way it can get information from RUN,....,....,STOP , and also RUN,STOP,STOP it will get RUN,....,STOP&lt;/P&gt;

&lt;P&gt;I hope you all understand what i meant.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 03:11:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498914#M138975</guid>
      <dc:creator>chookp</dc:creator>
      <dc:date>2020-03-23T03:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Transaction starts with ends with</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498915#M138976</link>
      <description>&lt;P&gt;@chookp post a couple of sample events to assist. &lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 04:13:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498915#M138976</guid>
      <dc:creator>anmolpatel</dc:creator>
      <dc:date>2020-03-26T04:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: Transaction starts with ends with</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498916#M138977</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/8564iC8D20F06CB23EF69/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;hi above is the sample of my event using the transaction to get each of my pump rum and stop duration, my issue is when there is a run run stop event it will take the latest run and first stop. &lt;BR /&gt;
below show my full list of event i did a MVindex so that you are able to see the full run stop event with the time.&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/8565i44856694AB2C45E1/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;the first picture show my transaction command which i did the information i circle is where i spot the error where it fail to detect my first "RUN". the second picture shows the full list of the event the part where i put a "?" is the missing infomation and the arrow pointing to it is the wrong RUN.&lt;/P&gt;

&lt;P&gt;so i would like to check is there a way to allow the transaction to take in the First "RUN" and first "Stop" that it sees or is there other command which i can compare the next value such that if its a RUN i can change the value of something, i hope this clarify my doubt thanks ..&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 07:32:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498916#M138977</guid>
      <dc:creator>chookp</dc:creator>
      <dc:date>2020-03-26T07:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: Transaction starts with ends with</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498917#M138978</link>
      <description>&lt;P&gt;What does the transaction command that's producing these results look like?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 14:42:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498917#M138978</guid>
      <dc:creator>rmmiller</dc:creator>
      <dc:date>2020-03-26T14:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: Transaction starts with ends with</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498918#M138979</link>
      <description>&lt;P&gt;Ditch &lt;CODE&gt;transaction&lt;/CODE&gt;; it is overkill and does not scale well.  Try this instead:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | streamstats count(eval(VALUE="STOP")) AS TransactionID BY ASSET_NAME 
| stats range(_time) AS duration list(VALUE) AS VALUES min(_time) AS _time BY TransactionID ASSET_NAME 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 26 Mar 2020 16:29:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498918#M138979</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-03-26T16:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: Transaction starts with ends with</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498919#M138980</link>
      <description>&lt;P&gt;Transaction ASSET_NAME startswith =VALUE=“RUN” endswith = VALUE=“STOP”&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 03:48:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498919#M138980</guid>
      <dc:creator>chookp</dc:creator>
      <dc:date>2020-03-27T03:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Transaction starts with ends with</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498920#M138981</link>
      <description>&lt;P&gt;Transaction ASSET_NAME startswith =VALUE=“RUN” endswith = VALUE=“STOP”&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2020 03:48:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498920#M138981</guid>
      <dc:creator>chookp</dc:creator>
      <dc:date>2020-03-27T03:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Transaction starts with ends with</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498921#M138982</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;... 
| reverse
| streamstats count(eval(VALUE="STOP")) AS TransactionID BY ASSET_NAME 
| stats range(_time) AS duration list(VALUE) AS VALUES min(_time) AS _time BY TransactionID ASSET_NAME 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transaction can use &lt;CODE&gt;eval&lt;/CODE&gt; , you can make condition other &lt;CODE&gt;startswith&lt;/CODE&gt; and &lt;CODE&gt;endswith&lt;/CODE&gt;&lt;BR /&gt;
but I recommend &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1406"&gt;@woodcock&lt;/a&gt; solution.&lt;/P&gt;

&lt;P&gt;This query &lt;CODE&gt;streamstats&lt;/CODE&gt;  is group by ASSET_NAME till &lt;EM&gt;VALUE="STOP"&lt;/EM&gt;&lt;BR /&gt;
Isn't this same as &lt;CODE&gt;transaction&lt;/CODE&gt;?&lt;/P&gt;

&lt;P&gt;If you need &lt;CODE&gt;duration&lt;/CODE&gt; and &lt;CODE&gt;linecount&lt;/CODE&gt; , try &lt;CODE&gt;range()&lt;/CODE&gt; and &lt;CODE&gt;count&lt;/CODE&gt;  with &lt;CODE&gt;stats&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;why do I add &lt;CODE&gt;reverse&lt;/CODE&gt;?  The new event is on the top by default.&lt;BR /&gt;
&lt;CODE&gt;streamstats&lt;/CODE&gt; works from top. need &lt;CODE&gt;reverse&lt;/CODE&gt; OR &lt;CODE&gt;sort 0 _time&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:44:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498921#M138982</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-09-30T04:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Transaction starts with ends with</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498922#M138983</link>
      <description>&lt;P&gt;Hi thanks for the help, i had tried the command it works well enough...but the problem is my field VALUE inside have “run,stop,normal,low,inconsistencies...etc” alot of different value, what i need is only from the first run to the first stop. Using your command they are adding the duration which I don’t need example the normal,low ,etc VALUE. Is there a way to just get RUN to STOP?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 08:18:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498922#M138983</guid>
      <dc:creator>chookp</dc:creator>
      <dc:date>2020-03-30T08:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Transaction starts with ends with</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498923#M138984</link>
      <description>&lt;P&gt;&lt;CODE&gt;In my data there is RUN,STOP,RUN,RUN,RUN,STOP,RUN,STOP,STOP,RUN,STOP.&lt;/CODE&gt;&lt;BR /&gt;
only first RUN and STOP?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 09:04:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498923#M138984</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-03-30T09:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: Transaction starts with ends with</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498924#M138985</link>
      <description>&lt;P&gt;Sure, just add this to the foundational search and keep the rest the same:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... AND (VALUE="RUN" OR VALUE="STOP") ...
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 30 Mar 2020 19:50:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498924#M138985</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-03-30T19:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Transaction starts with ends with</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498925#M138986</link>
      <description>&lt;P&gt;thanks everything works nicely now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 02:47:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-starts-with-ends-with/m-p/498925#M138986</guid>
      <dc:creator>chookp</dc:creator>
      <dc:date>2020-04-01T02:47:37Z</dc:date>
    </item>
  </channel>
</rss>

