<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Postfix Queue ID in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Postfix-Queue-ID/m-p/9832#M281</link>
    <description>&lt;P&gt;I think you're looking for the transaction feature: &lt;A href="http://www.splunk.com/base/Documentation/4.0.9/Knowledge/Abouttransactions" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.0.9/Knowledge/Abouttransactions&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Transactions combine together multiple events with some automatically created fields like how long the transaction took.&lt;/P&gt;

&lt;P&gt;They can be defined ad-hoc as part of a search: &lt;A href="http://www.splunk.com/base/Documentation/4.0.9/SearchReference/Transaction" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.0.9/SearchReference/Transaction&lt;/A&gt;  or the &lt;/P&gt;

&lt;P&gt;Or they can be stored/persisted in configuration: &lt;A href="http://www.splunk.com/base/Documentation/4.0.9/Knowledge/Definetransactions" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.0.9/Knowledge/Definetransactions&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 20 Feb 2010 06:03:20 GMT</pubDate>
    <dc:creator>jrodman</dc:creator>
    <dc:date>2010-02-20T06:03:20Z</dc:date>
    <item>
      <title>Postfix Queue ID</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Postfix-Queue-ID/m-p/9830#M279</link>
      <description>&lt;P&gt;I've been able to extract Postfix Queue ID's out of sourcetype="postfix_syslog" however often logs have multiple Queue ID's, and I'd like to extract the ID's, and use them to build transaction across postfix log events, events where postfix hands the logs off to another process, such as amavis and when one MTA hands the message to another server in the farm, allowing me to build the complete transaction of a mail message from acceptance at the border, filtering and final delivery! Has anyone been able to write an extraction the takes events with two Queue ID's and correctly maps the "Secondary" to the "Primary" in a related event?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2010 01:09:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Postfix-Queue-ID/m-p/9830#M279</guid>
      <dc:creator>thartmann</dc:creator>
      <dc:date>2010-02-20T01:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: Postfix Queue ID</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Postfix-Queue-ID/m-p/9831#M280</link>
      <description>&lt;P&gt;So what's the question, how to extract mulitple Q ID's? How to build a transaction?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2010 01:44:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Postfix-Queue-ID/m-p/9831#M280</guid>
      <dc:creator>Mick</dc:creator>
      <dc:date>2010-02-20T01:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Postfix Queue ID</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Postfix-Queue-ID/m-p/9832#M281</link>
      <description>&lt;P&gt;I think you're looking for the transaction feature: &lt;A href="http://www.splunk.com/base/Documentation/4.0.9/Knowledge/Abouttransactions" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.0.9/Knowledge/Abouttransactions&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Transactions combine together multiple events with some automatically created fields like how long the transaction took.&lt;/P&gt;

&lt;P&gt;They can be defined ad-hoc as part of a search: &lt;A href="http://www.splunk.com/base/Documentation/4.0.9/SearchReference/Transaction" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.0.9/SearchReference/Transaction&lt;/A&gt;  or the &lt;/P&gt;

&lt;P&gt;Or they can be stored/persisted in configuration: &lt;A href="http://www.splunk.com/base/Documentation/4.0.9/Knowledge/Definetransactions" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/4.0.9/Knowledge/Definetransactions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2010 06:03:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Postfix-Queue-ID/m-p/9832#M281</guid>
      <dc:creator>jrodman</dc:creator>
      <dc:date>2010-02-20T06:03:20Z</dc:date>
    </item>
    <item>
      <title>Re: Postfix Queue ID</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Postfix-Queue-ID/m-p/9833#M282</link>
      <description>&lt;P&gt;Can you add a sample line(s) from the log you're trying to use? I think you're asking about how to create a transaction when there are multiple QID values in the same log line, but seeing examples of the specific events you're trying to handle will be helpful to clarify.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2010 03:28:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Postfix-Queue-ID/m-p/9833#M282</guid>
      <dc:creator>Justin_Grant</dc:creator>
      <dc:date>2010-02-23T03:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: Postfix Queue ID</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Postfix-Queue-ID/m-p/9834#M283</link>
      <description>&lt;P&gt;Jrodmap,&lt;BR /&gt;
The problem is not so easy and doc doesn't help. I've been doing the same here with a prospect customer. Transaction can't fully help becuse the several events to correlate never have ALL the same fields needed to "transaction" command. The transaction flows from one log to the other, and the startling identifying field (queue_id) then must be linked to the "from" field and a "message_id" in the amavis logs.&lt;/P&gt;

&lt;P&gt;So, how is it possible to link events correlated from a chain of different fields?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
marco&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:33:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Postfix-Queue-ID/m-p/9834#M283</guid>
      <dc:creator>marcoscala</dc:creator>
      <dc:date>2020-09-28T11:33:21Z</dc:date>
    </item>
  </channel>
</rss>

