<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Query in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697964#M237068</link>
    <description>&lt;P&gt;You can add channel to all events with the same tran_id with eventstats&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eventstats values(channel) as channel by tran_id&lt;/LI-CODE&gt;</description>
    <pubDate>Mon, 02 Sep 2024 10:08:18 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2024-09-02T10:08:18Z</dc:date>
    <item>
      <title>Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697888#M237044</link>
      <description>&lt;P&gt;I would like to calculate the success rate of the Toup transaction via Channel( APP Or Web) in 4 API calls( E.g 4 Levels,Request will submit 1 do the validation and pass on level 2 and then at level 2 will do business validation and pass the transaction to next level and so on) in that few transactions may fail at level 1/2/3/4.&amp;nbsp; The channel method will be available only in the Level 1 not in the Other level. Transaction ID is the only field comman in all the levels. If I apply filter on Channel the output only the list of transaction in Level 1 since Channel field available in level1.&lt;/P&gt;&lt;P&gt;1. If apply filter on Web/APP Channel I should get the list of transaction IDs respective of channel&lt;/P&gt;&lt;P&gt;2. Taking the transaction IDs as a input it should the validate the status of the transaction at each level (2/3/4).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: In level 2/3/4 the log has both App and web logs only based on the transaction ID from level 1 need to differentiate.&lt;/P&gt;&lt;P&gt;Https status -200(Success); 500(Failure)&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 12:33:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697888#M237044</guid>
      <dc:creator>dinesh001kumar</dc:creator>
      <dc:date>2024-09-01T12:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697893#M237046</link>
      <description>&lt;P&gt;Please share some raw anonymised representative sample events in a code block to preserve formatting.&lt;/P&gt;&lt;P&gt;Please identify which fields (if any) you already have extracted.&lt;/P&gt;&lt;P&gt;Also, please share a representation of your expected output.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 14:32:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697893#M237046</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-09-01T14:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697904#M237050</link>
      <description>&lt;P&gt;Level: 1&lt;/P&gt;&lt;P&gt;Time:01/09/2024&amp;nbsp; 12:00:00.230&lt;BR /&gt;call_headers: "{\"platform\":\"android\",\"user-agent\\"device-id\":\"380C71F2-6546-3340D56648g\",\"channel\":\"APP\"}"&lt;BR /&gt;call_severity: 1&lt;BR /&gt;log_env: test&lt;BR /&gt;message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;tran_id: dghhaxkhhjxh00765sg&lt;/P&gt;&lt;P&gt;===========================================================================================================&lt;/P&gt;&lt;P&gt;Level: 2&lt;/P&gt;&lt;P&gt;Time:01/09/2024&amp;nbsp; 12:02:00.230&lt;BR /&gt;http_status: 200&lt;BR /&gt;call_severity: 1&lt;BR /&gt;log_env: test&lt;BR /&gt;message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;tran_id: dghhaxkhhjxh00765sg&lt;BR /&gt;==========================================================================================================&lt;BR /&gt;Level: 3&lt;/P&gt;&lt;P&gt;Time:01/09/2024&amp;nbsp; 12:00:10.220&lt;BR /&gt;Req_domain: &lt;A href="https://google.com/purchaseproduct" target="_blank"&gt;https://google.com/purchaseproduct&lt;/A&gt;&lt;BR /&gt;Req_method: POST&lt;BR /&gt;log_env: test&lt;BR /&gt;message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;tran_id: dghhaxkhhjxh00765sg&lt;BR /&gt;==========================================================================================================&lt;BR /&gt;Level: 4&lt;/P&gt;&lt;P&gt;Time:01/09/2024&amp;nbsp; 12:00:30.230&lt;BR /&gt;http_status: 200&lt;BR /&gt;Status:Completed&lt;BR /&gt;log_env: test&lt;BR /&gt;message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;tran_id: dghhaxkhhjxh00765sg&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 17:38:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697904#M237050</guid>
      <dc:creator>dinesh001kumar</dc:creator>
      <dc:date>2024-09-01T17:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697905#M237051</link>
      <description>&lt;P&gt;Level: 1&lt;BR /&gt;call_headers: "{\"platform\":\"android\",\"user-agent\\"device-id\":\"380C71F2-6546-3340D56648g\",\"channel\":\"web\"}"&lt;BR /&gt;call_severity: 1&lt;BR /&gt;log_env: test&lt;BR /&gt;message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;tran_id: tdgdbdjkksolsksujj&lt;/P&gt;&lt;P&gt;===========================================================================================================&lt;/P&gt;&lt;P&gt;Level: 2&lt;BR /&gt;http_status: 200&lt;BR /&gt;call_severity: 1&lt;BR /&gt;log_env: test&lt;BR /&gt;message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;tran_id: tdgdbdjkksolsksujj&lt;BR /&gt;==========================================================================================================&lt;BR /&gt;Level: 3&lt;BR /&gt;Req_domain: &lt;A href="https://google.com/purchaseproduct" target="_blank"&gt;https://google.com/purchaseproduct&lt;/A&gt;&lt;BR /&gt;Req_method: POST&lt;BR /&gt;log_env: test&lt;BR /&gt;message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;tran_id: tdgdbdjkksolsksujj&lt;BR /&gt;==========================================================================================================&lt;BR /&gt;Level: 4&lt;BR /&gt;http_status: 200&lt;BR /&gt;Status:Completed&lt;BR /&gt;log_env: test&lt;BR /&gt;message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;tran_id: tdgdbdjkksolsksujj&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 17:40:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697905#M237051</guid>
      <dc:creator>dinesh001kumar</dc:creator>
      <dc:date>2024-09-01T17:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697907#M237052</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Above is the 2 Sample events with transactionID, the log pattern will be same but only the Channel and Transaction ID will get different, So If Apply filter at Channel level its getting reflected the Level 1 Event only, Since there is no Channel event in remaining 3 events. I need to calculate whether the transaction is successfully passed at all level or failed in between.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 17:43:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697907#M237052</guid>
      <dc:creator>dinesh001kumar</dc:creator>
      <dc:date>2024-09-01T17:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697911#M237055</link>
      <description>&lt;P&gt;I am not seeing the sample events in a code block - please can you repost them&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2024 20:05:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697911#M237055</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-09-01T20:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697922#M237058</link>
      <description>&lt;P&gt;Level: 1&lt;BR /&gt;call_headers: "{\"platform\":\"android\",\"user-agent\\"device-id\":\"380C71F2-6546-3340D56648g\",\"channel\":\"web\"}"&lt;/P&gt;&lt;P&gt;Channel:web&lt;BR /&gt;call_severity: 1&lt;BR /&gt;log_env: test&lt;BR /&gt;message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;tran_id: tdgdbdjkksolsksujj&lt;/P&gt;&lt;P&gt;===========================================================================================================&lt;/P&gt;&lt;P&gt;Level: 2&lt;BR /&gt;http_status: 200&lt;BR /&gt;call_severity: 1&lt;BR /&gt;log_env: test&lt;BR /&gt;message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;tran_id: tdgdbdjkksolsksujj&lt;BR /&gt;==========================================================================================================&lt;BR /&gt;Level: 3&lt;BR /&gt;Req_domain:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://google.com/purchaseproduct" target="_blank" rel="nofollow noopener noreferrer"&gt;https://google.com/purchaseproduct&lt;/A&gt;&lt;BR /&gt;Req_method: POST&lt;BR /&gt;log_env: test&lt;BR /&gt;message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;tran_id: tdgdbdjkksolsksujj&lt;BR /&gt;==========================================================================================================&lt;BR /&gt;Level: 4&lt;BR /&gt;http_status: 200&lt;BR /&gt;Status:Completed&lt;BR /&gt;log_env: test&lt;BR /&gt;message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b&lt;BR /&gt;tran_id: tdgdbdjkksolsksujj&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 04:11:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697922#M237058</guid>
      <dc:creator>dinesh001kumar</dc:creator>
      <dc:date>2024-09-02T04:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697923#M237059</link>
      <description>&lt;P&gt;Level: 1&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Time:01/09/2024  12:00:00.230
call_headers: "{\"platform\":\"android\",\"user-agent\\"device-id\":\"380C71F2-6546-3340D56648g\",\"channel\":\"APP\"}"

Channel:App
call_severity: 1
log_env: test
message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b
Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b
tran_id: dghhaxkhhjxh00765sg&lt;/LI-CODE&gt;
&lt;P&gt;===========================================================================================================&lt;/P&gt;
&lt;P&gt;Level: 2&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Time:01/09/2024  12:02:00.230
http_status: 200
call_severity: 1
log_env: test
message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b
Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b
tran_id: dghhaxkhhjxh00765sg&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;==========================================================================================================&lt;BR /&gt;Level: 3&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Time:01/09/2024  12:00:10.220
Req_domain: https://google.com/purchaseproduct
Req_method: POST
log_env: test
message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b
Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b
tran_id: dghhaxkhhjxh00765sg&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;==========================================================================================================&lt;BR /&gt;Level: 4&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Time:01/09/2024  12:00:30.230
http_status: 200
Status:Completed
log_env: test
message: /api/subscriptiontypes/Prepaid/products/10669413a39dee7fcd8422d80826067b
Function: /api/producttypes/Prepaid/products/10669413a39dee7fcd8422d80826067b
tran_id: dghhaxkhhjxh00765sg&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 02 Sep 2024 10:04:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697923#M237059</guid>
      <dc:creator>dinesh001kumar</dc:creator>
      <dc:date>2024-09-02T10:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697924#M237060</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have reposted the sample 2 sample logs &lt;SPAN&gt;with transactionID,&lt;/SPAN&gt;&amp;nbsp;Please consider the Channel as a field,&amp;nbsp;&lt;SPAN&gt;the log pattern will be same but only the Channel and Transaction ID will get different, So If Apply filter at Channel level its getting reflected the Level 1 Event only, Since there is no Channel event in remaining 3 events. I need to calculate whether the transaction is successfully passed at all level or failed in between.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 04:15:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697924#M237060</guid>
      <dc:creator>dinesh001kumar</dc:creator>
      <dc:date>2024-09-02T04:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Query</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697964#M237068</link>
      <description>&lt;P&gt;You can add channel to all events with the same tran_id with eventstats&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eventstats values(channel) as channel by tran_id&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 02 Sep 2024 10:08:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Query/m-p/697964#M237068</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-09-02T10:08:18Z</dc:date>
    </item>
  </channel>
</rss>

