<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Display transaction result in a table in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21195#M3448</link>
    <description>&lt;P&gt;as Ayn already stated, why don't just use the table command next?&lt;/P&gt;</description>
    <pubDate>Thu, 07 Feb 2013 06:56:01 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2013-02-07T06:56:01Z</dc:date>
    <item>
      <title>How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21184#M3437</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I have a search using transaction command&lt;BR /&gt;
&lt;CODE&gt;mysearch | transaction startswith=start endswith=end&lt;/CODE&gt;&lt;BR /&gt;
and I am getting several events as one event, i would like those events to be displayed in a table.&lt;/P&gt;

&lt;P&gt;Is it possible to do so??&lt;BR /&gt;
please help&lt;BR /&gt;
Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 04:36:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21184#M3437</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2013-02-06T04:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21185#M3438</link>
      <description>&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/48576/nested-transactionstables"&gt;something related to this,&lt;/A&gt; but i my transaction uses startwith and endswith, i need tables in expanded form, now they are displaying as if i used list() ot values() i want it to be exactly like a normal table... any thoughts????&lt;BR /&gt;
please help&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 06:03:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21185#M3438</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2013-02-06T06:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21186#M3439</link>
      <description>&lt;P&gt;So you're combining multiple events into one event, then you want that event to be displayed as...multiple events again?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 09:42:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21186#M3439</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-02-06T09:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21187#M3440</link>
      <description>&lt;P&gt;smolcj, can you explain your use case more fully?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 11:12:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21187#M3440</guid>
      <dc:creator>dart</dc:creator>
      <dc:date>2013-02-06T11:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21188#M3441</link>
      <description>&lt;P&gt;a table command after transaction can do the job&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 11:30:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21188#M3441</guid>
      <dc:creator>bellaed</dc:creator>
      <dc:date>2013-02-06T11:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21189#M3442</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
i dont want events as multivalued as because these events can be read through transaction command i did so.&lt;BR /&gt;
i wan them to be in tables&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 12:58:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21189#M3442</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2013-02-06T12:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21190#M3443</link>
      <description>&lt;P&gt;Which events, the pre-transaction individual events or the combined events that transaction creates?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 13:00:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21190#M3443</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-02-06T13:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21191#M3444</link>
      <description>&lt;P&gt;Ayn, combined events that transaction creates should be displayed in tables and thereafter i have to use re-director to one of the field like severity.. i need to display all the events between specific keywords that is the reason i used transaction command&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 13:03:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21191#M3444</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2013-02-06T13:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21192#M3445</link>
      <description>&lt;P&gt;So if it's the combined events you want to show, what's stopping you from using table?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 13:23:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21192#M3445</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-02-06T13:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21193#M3446</link>
      <description>&lt;P&gt;I think a good idea would be to provide a few sample events, and a sketch of how you want the output.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2013 14:38:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21193#M3446</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-02-06T14:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21194#M3447</link>
      <description>&lt;P&gt;My log events are like this &lt;/P&gt;

&lt;P&gt;timestamp ... event start ..&lt;BR /&gt;
.&lt;BR /&gt;
....some other events&lt;BR /&gt;
.&lt;BR /&gt;
timestamp... event end&lt;BR /&gt;
.&lt;BR /&gt;
.&lt;BR /&gt;
timestamp..another eventstart&lt;BR /&gt;
.&lt;BR /&gt;
.&lt;BR /&gt;
event end&lt;/P&gt;

&lt;P&gt;So inorder to display all the events between start and stop i used transaction command&lt;BR /&gt;
... | transaction startswith= "event star" ends with ="event end".. but i want those events to be displayed in tables.. How could i , is there any other alternative for transaction command? &lt;BR /&gt;
Please help&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2013 04:53:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21194#M3447</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2013-02-07T04:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21195#M3448</link>
      <description>&lt;P&gt;as Ayn already stated, why don't just use the table command next?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2013 06:56:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21195#M3448</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2013-02-07T06:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21196#M3449</link>
      <description>&lt;P&gt;i am not getting proper table .. the values are deduplicated , for example if the severity is info for 5 events, it will show only once, something like we used values(field) or list (field).. i am in need of exact table &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2013 06:59:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21196#M3449</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2013-02-07T06:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21197#M3450</link>
      <description>&lt;P&gt;like kkolb said: provide some samples, real samples of your log events. perhaps we are then able to help.....&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2013 08:56:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21197#M3450</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2013-02-07T08:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21198#M3451</link>
      <description>&lt;P&gt;I am using this search index=main source=file.txt|transaction startswith=TM_6000 endswith=TM_6020 maxevents=10000&lt;BR /&gt;
and my output is like &lt;IMG src="http://splunk-base.splunk.com//storage/Untitled_13.png" alt="alt text" /&gt;&lt;BR /&gt;
It looks so crappy and i am not able to use redirection for this ... appending a table command after transaction gives&lt;BR /&gt;
&lt;IMG src="http://splunk-base.splunk.com//storage/Untitled1_6.png" alt="alt text" /&gt;&lt;BR /&gt;
i want it as a normal table  that i can provide external links to some of the field&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:15:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21198#M3451</guid>
      <dc:creator>smolcj</dc:creator>
      <dc:date>2020-09-28T13:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21199#M3452</link>
      <description>&lt;P&gt;I think you want:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;mysearch | transaction startswith=start endswith=end mvlist=t | table field1, field2, field3
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;By default transaction will "group" like values, mvlist tells it to display repeated values in your resulting table&lt;/P&gt;

&lt;P&gt;The next issue i haven't figured out yet will be if you need to export the results. . .&lt;/P&gt;</description>
      <pubDate>Sun, 21 Apr 2013 05:19:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21199#M3452</guid>
      <dc:creator>gwallin042</dc:creator>
      <dc:date>2013-04-21T05:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to Display transaction result in a table</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21200#M3453</link>
      <description>&lt;P&gt;Just to follow up as I had a similar issue, I think that you can get all the lines that each transaction returns into a single row by using _raw as your field e.g.&lt;/P&gt;

&lt;P&gt;transaction   | table _raw field1 field2 etc etc&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2017 08:27:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-Display-transaction-result-in-a-table/m-p/21200#M3453</guid>
      <dc:creator>nmulm</dc:creator>
      <dc:date>2017-09-22T08:27:45Z</dc:date>
    </item>
  </channel>
</rss>

