<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why when I use transaction command, search is not extracting some fields in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-when-I-use-transaction-command-search-is-not-extracting-some/m-p/599761#M208748</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;try to use transaction command, but actionName is empty!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is my SPL&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt; |  rex "actionName.*\.(?&amp;lt;actionName&amp;gt;\w+\.\w+)\]" | rex "duration\[(?&amp;lt;duration&amp;gt;\d+)"
 | rex "transactionId\[(?&amp;lt;transactionId&amp;gt;\w+-\w+-\w+-\w+-\w+)"
 |transaction transactionId
 | table duration actionName username&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Here is the current result:&lt;/P&gt;
&lt;P&gt;duration &amp;nbsp;&amp;nbsp; actionName&amp;nbsp;&amp;nbsp;&amp;nbsp; username&amp;nbsp;&amp;nbsp;&lt;BR /&gt;171847&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ABC&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the expected result:&lt;/P&gt;
&lt;P&gt;duration &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; actionName&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; username&amp;nbsp;&amp;nbsp;&lt;BR /&gt;171847&amp;nbsp;&amp;nbsp;&amp;nbsp; QueryOnData.Allow&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ABC&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the log:&lt;BR /&gt;2022-05-30 12:39:34,262 INFO&amp;nbsp; [APP] [Act] actionName[us.st.zxc.asda.app.session.protector.QueryOnData.Allow] parameters[] transactionId[8d135d45-c117-4781-a3ed-9a6a9db7ce4d] username[ABC] startTime[1653898174262]&lt;BR /&gt;&lt;BR /&gt;2022-05-30 12:42:26,109 INFO&amp;nbsp; [APP] [Act] actionName[us.st.zxc.asda.app.session.protector.QueryOnData.Allow] transactionId[8d135d45-c117-4781-a3ed-9a6a9db7ce4d] duration[171847] status[done]&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 13:55:40 GMT</pubDate>
    <dc:creator>indeed_2000</dc:creator>
    <dc:date>2022-05-31T13:55:40Z</dc:date>
    <item>
      <title>Why when I use transaction command, search is not extracting some fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-when-I-use-transaction-command-search-is-not-extracting-some/m-p/599761#M208748</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;try to use transaction command, but actionName is empty!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is my SPL&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt; |  rex "actionName.*\.(?&amp;lt;actionName&amp;gt;\w+\.\w+)\]" | rex "duration\[(?&amp;lt;duration&amp;gt;\d+)"
 | rex "transactionId\[(?&amp;lt;transactionId&amp;gt;\w+-\w+-\w+-\w+-\w+)"
 |transaction transactionId
 | table duration actionName username&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Here is the current result:&lt;/P&gt;
&lt;P&gt;duration &amp;nbsp;&amp;nbsp; actionName&amp;nbsp;&amp;nbsp;&amp;nbsp; username&amp;nbsp;&amp;nbsp;&lt;BR /&gt;171847&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ABC&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the expected result:&lt;/P&gt;
&lt;P&gt;duration &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; actionName&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; username&amp;nbsp;&amp;nbsp;&lt;BR /&gt;171847&amp;nbsp;&amp;nbsp;&amp;nbsp; QueryOnData.Allow&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ABC&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the log:&lt;BR /&gt;2022-05-30 12:39:34,262 INFO&amp;nbsp; [APP] [Act] actionName[us.st.zxc.asda.app.session.protector.QueryOnData.Allow] parameters[] transactionId[8d135d45-c117-4781-a3ed-9a6a9db7ce4d] username[ABC] startTime[1653898174262]&lt;BR /&gt;&lt;BR /&gt;2022-05-30 12:42:26,109 INFO&amp;nbsp; [APP] [Act] actionName[us.st.zxc.asda.app.session.protector.QueryOnData.Allow] transactionId[8d135d45-c117-4781-a3ed-9a6a9db7ce4d] duration[171847] status[done]&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 13:55:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-when-I-use-transaction-command-search-is-not-extracting-some/m-p/599761#M208748</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2022-05-31T13:55:40Z</dc:date>
    </item>
    <item>
      <title>Re: transaction command not extract some fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-when-I-use-transaction-command-search-is-not-extracting-some/m-p/599763#M208749</link>
      <description>&lt;P&gt;You have extracted actionName as method - try it this way&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; |  rex "actionName.*\.(?&amp;lt;actionName&amp;gt;\w+\.\w+)\]"&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 30 May 2022 16:32:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-when-I-use-transaction-command-search-is-not-extracting-some/m-p/599763#M208749</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-05-30T16:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: transaction command not extract some fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-when-I-use-transaction-command-search-is-not-extracting-some/m-p/599764#M208750</link>
      <description>&lt;P&gt;sorry it was typo, modify post. result same and still not work.&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 16:38:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-when-I-use-transaction-command-search-is-not-extracting-some/m-p/599764#M208750</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2022-05-30T16:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: transaction command not extract some fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-when-I-use-transaction-command-search-is-not-extracting-some/m-p/599765#M208751</link>
      <description>&lt;P&gt;There doesn't appear to be anything wrong with your rex expressions (given the examples you provided). However, you could try it this way&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;|  rex "actionName\[(\w+\.)*(?&amp;lt;actionName&amp;gt;\w+\.\w+)\]" &lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 30 May 2022 16:53:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-when-I-use-transaction-command-search-is-not-extracting-some/m-p/599765#M208751</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-05-30T16:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: transaction command not extract some fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-when-I-use-transaction-command-search-is-not-extracting-some/m-p/599767#M208752</link>
      <description>&lt;P&gt;Thank you now actionName show correctly .&lt;/P&gt;&lt;P&gt;I encounter with another strange issue when i use transaction and at the end sort by duration it show highest duration is 15000 but when i remove transaction it show 17000 as highest duration!!!&lt;/P&gt;&lt;P&gt;FYI1:correct value is 17000 and there is no special filter exist here!&lt;/P&gt;&lt;P&gt;FYI2:duration directly print in log i just use transaction to aggregate two lines.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is with transaction command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;|&amp;nbsp; rex "actionName.*\.(?&amp;lt;actionName&amp;gt;\w+\.\w+)\]" | rex "duration\[(?&amp;lt;duration&amp;gt;\d+)"&lt;BR /&gt;&amp;nbsp;| rex "transactionId\[(?&amp;lt;transactionId&amp;gt;\w+-\w+-\w+-\w+-\w+)"&lt;BR /&gt;&amp;nbsp;|transaction transactionId | sort - duration&lt;BR /&gt;&amp;nbsp;| table duration actionName username&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is without transaction:&lt;/P&gt;&lt;P&gt;&amp;nbsp;|&amp;nbsp; rex "actionName.*\.(?&amp;lt;actionName&amp;gt;\w+\.\w+)\]" | rex "duration\[(?&amp;lt;duration&amp;gt;\d+)"&lt;BR /&gt;&amp;nbsp;| rex "transactionId\[(?&amp;lt;transactionId&amp;gt;\w+-\w+-\w+-\w+-\w+)"&lt;BR /&gt;| sort - duration&lt;BR /&gt;&amp;nbsp;| table duration actionName username&lt;/P&gt;&lt;P&gt;any idea?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2022 17:29:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-when-I-use-transaction-command-search-is-not-extracting-some/m-p/599767#M208752</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2022-05-30T17:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: transaction command not extract some fields</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-when-I-use-transaction-command-search-is-not-extracting-some/m-p/599799#M208768</link>
      <description>&lt;P&gt;Answered here&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Splunk-Search/Transaction-command-not-work-as-expcted/m-p/599797#M208767" target="_blank"&gt;Re: Transaction command not work as expcted - Splunk Community&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 06:17:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-when-I-use-transaction-command-search-is-not-extracting-some/m-p/599799#M208768</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2022-05-31T06:17:31Z</dc:date>
    </item>
  </channel>
</rss>

