<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filter transaction in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667384#M228957</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;you miss main question and I tell you step by step main question!&lt;/P&gt;&lt;P&gt;Would you please check main question? And tell me is there any way to do that?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Sat, 04 Nov 2023 18:20:31 GMT</pubDate>
    <dc:creator>indeed_2000</dc:creator>
    <dc:date>2023-11-04T18:20:31Z</dc:date>
    <item>
      <title>Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667285#M228922</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;i have log line like this,&lt;/P&gt;&lt;P&gt;1-need to group by them by ID,&lt;/P&gt;&lt;P&gt;2- filter those transactions that has T[A]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;#txn1&lt;BR /&gt;&lt;SPAN&gt;16:30:53:002 moduleA ID[123]&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;16:30:54:002 moduleA ID[123]&lt;BR /&gt;&lt;/SPAN&gt;16:30:55:002 moduleB ID[123]T[A]&lt;BR /&gt;16:30:56:002 moduleC ID[123]&lt;BR /&gt;&lt;BR /&gt;#txn2&lt;BR /&gt;16:30:57:002 moduleD ID[987]&lt;BR /&gt;16:30:58:002 moduleE ID[987]T[B]&lt;BR /&gt;16:30:59:002 moduleF ID[987]&lt;BR /&gt;16:30:60:002 moduleZ ID[987]&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 10:24:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667285#M228922</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2023-11-03T10:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667287#M228924</link>
      <description>&lt;P&gt;What fields do you already have extracted?&lt;/P&gt;&lt;P&gt;By "filter" do you mean filter in or filter out i.e. do you want to keep the events with T[A], keep only those events with T[A] or remove them altogether?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 10:57:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667287#M228924</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-03T10:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667345#M228932</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;need to see filter out/in result to decide.&lt;/P&gt;&lt;P&gt;All fields extracted already.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;need keep the events with T[A].&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 17:15:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667345#M228932</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2023-11-03T17:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667351#M228935</link>
      <description>&lt;LI-CODE lang="markup"&gt;| sort 0 ID&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 03 Nov 2023 19:02:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667351#M228935</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-03T19:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667353#M228936</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 19:13:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667353#M228936</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2023-11-03T19:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667354#M228937</link>
      <description>&lt;P&gt;Your events will be together by ID&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 19:25:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667354#M228937</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-03T19:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667355#M228938</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How about other part?&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI: i mean extract key value one by one with rex command not whole transaction.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 20:01:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667355#M228938</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2023-11-03T20:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667357#M228939</link>
      <description>&lt;P&gt;Not sure I understand, you just said all fields already extracted?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 20:52:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667357#M228939</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-03T20:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667358#M228940</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;i mean id, t , … key value extracted not transaction.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2023 21:04:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667358#M228940</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2023-11-03T21:04:08Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667370#M228946</link>
      <description>&lt;P&gt;What do you mean by transaction?&lt;/P&gt;</description>
      <pubDate>Sat, 04 Nov 2023 10:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667370#M228946</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-04T10:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667377#M228952</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;#txn1&lt;BR /&gt;&lt;SPAN&gt;16:30:53:002 moduleA ID[123]&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;16:30:54:002 moduleA ID[123]&lt;BR /&gt;&lt;/SPAN&gt;16:30:55:002 moduleB ID[123]T[A]&lt;BR /&gt;16:30:56:002 moduleC ID[123]&lt;BR /&gt;&lt;BR /&gt;#txn2&lt;BR /&gt;16:30:57:002 moduleD ID[987]&lt;BR /&gt;16:30:58:002 moduleE ID[987]T[B]&lt;BR /&gt;16:30:59:002 moduleF ID[987]&lt;BR /&gt;16:30:60:002 moduleZ ID[987]&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Nov 2023 14:49:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667377#M228952</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2023-11-04T14:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667379#M228953</link>
      <description>&lt;P&gt;How do you determine which events are part of a "transaction"?&lt;/P&gt;</description>
      <pubDate>Sat, 04 Nov 2023 16:23:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667379#M228953</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-04T16:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667380#M228954</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;group by id&lt;/P&gt;</description>
      <pubDate>Sat, 04 Nov 2023 16:25:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667380#M228954</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2023-11-04T16:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667382#M228955</link>
      <description>&lt;LI-CODE lang="markup"&gt;| stats list(_raw) as _raw by ID&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 04 Nov 2023 16:31:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667382#M228955</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-04T16:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667384#M228957</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;you miss main question and I tell you step by step main question!&lt;/P&gt;&lt;P&gt;Would you please check main question? And tell me is there any way to do that?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sat, 04 Nov 2023 18:20:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667384#M228957</guid>
      <dc:creator>indeed_2000</dc:creator>
      <dc:date>2023-11-04T18:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: Filter transaction</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667389#M228959</link>
      <description>&lt;LI-CODE lang="markup"&gt;| stats list(_raw) as _raw list(T) as T by ID
| where T=="A"&lt;/LI-CODE&gt;</description>
      <pubDate>Sat, 04 Nov 2023 20:09:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-transaction/m-p/667389#M228959</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-04T20:09:21Z</dc:date>
    </item>
  </channel>
</rss>

