<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Transaction not providing all events in target range. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Transaction-not-providing-all-events-in-target-range/m-p/161498#M45674</link>
    <description>&lt;P&gt;Howdy:&lt;BR /&gt;
I'm a new Splunker so this may be a dumb question. I have looked around splunk&amp;gt;Answers and couldn't find a solution to my problem, So here it goes. Using Splunk Enterprise 6.1.2 on Mac OS X.&lt;/P&gt;

&lt;P&gt;transactiontypes.conf has this definition:&lt;/P&gt;

&lt;P&gt;[aaRegistration]&lt;BR /&gt;
maxspan = 2h&lt;BR /&gt;
maxpause = 2h&lt;BR /&gt;
maxevents = 10000&lt;BR /&gt;
unifyends = t&lt;BR /&gt;
fields = _time, host, _raw&lt;BR /&gt;
startswith = "::aaRegistration"&lt;BR /&gt;
endswith = "aa"&lt;/P&gt;

&lt;P&gt;The indexed events already loaded into Splunk look like this:&lt;BR /&gt;
...&lt;BR /&gt;
&lt;DATESTAMP&gt;  aaRegistration&lt;BR /&gt;
...&lt;BR /&gt;
... events during “aaRegistration” phase, all with datestamp&lt;BR /&gt;
...&lt;BR /&gt;
&lt;DATESTAMP&gt; aaCalibration&lt;BR /&gt;
..&lt;BR /&gt;
.... events during “aaCalibration” phase, all with datestamp&lt;BR /&gt;
...&lt;BR /&gt;
&lt;DATESTAMP&gt; aaInfo&lt;BR /&gt;
...&lt;BR /&gt;
... events during “aaInfo” phase&lt;BR /&gt;
...&lt;BR /&gt;
&lt;DATESTAMP&gt; aaMarks&lt;BR /&gt;
...&lt;BR /&gt;
... events during “aaMarks” phase, all with datestamp&lt;BR /&gt;
...&lt;/DATESTAMP&gt;&lt;/DATESTAMP&gt;&lt;/DATESTAMP&gt;&lt;/DATESTAMP&gt;&lt;/P&gt;

&lt;P&gt;When I search with this:&lt;BR /&gt;
host=hostA sourcetype="typeB" earliest="05/02/2014:00:00:00" latest="05/03/2014:00:00:00" | transaction name=aaRegistration&lt;/P&gt;

&lt;P&gt;The result does show the one event that starts the transaction. But I do not get any of the events between the start and the end, just a single event.&lt;/P&gt;

&lt;P&gt;Question: what do I need to change to be able to see a list of &lt;EM&gt;all&lt;/EM&gt; events that occurred between the start and the end of the “aaRegistration” phase?&lt;/P&gt;

&lt;P&gt;Pointers appreciated. Thanks.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jul 2014 14:59:38 GMT</pubDate>
    <dc:creator>jlacal</dc:creator>
    <dc:date>2014-07-29T14:59:38Z</dc:date>
    <item>
      <title>Transaction not providing all events in target range.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-not-providing-all-events-in-target-range/m-p/161498#M45674</link>
      <description>&lt;P&gt;Howdy:&lt;BR /&gt;
I'm a new Splunker so this may be a dumb question. I have looked around splunk&amp;gt;Answers and couldn't find a solution to my problem, So here it goes. Using Splunk Enterprise 6.1.2 on Mac OS X.&lt;/P&gt;

&lt;P&gt;transactiontypes.conf has this definition:&lt;/P&gt;

&lt;P&gt;[aaRegistration]&lt;BR /&gt;
maxspan = 2h&lt;BR /&gt;
maxpause = 2h&lt;BR /&gt;
maxevents = 10000&lt;BR /&gt;
unifyends = t&lt;BR /&gt;
fields = _time, host, _raw&lt;BR /&gt;
startswith = "::aaRegistration"&lt;BR /&gt;
endswith = "aa"&lt;/P&gt;

&lt;P&gt;The indexed events already loaded into Splunk look like this:&lt;BR /&gt;
...&lt;BR /&gt;
&lt;DATESTAMP&gt;  aaRegistration&lt;BR /&gt;
...&lt;BR /&gt;
... events during “aaRegistration” phase, all with datestamp&lt;BR /&gt;
...&lt;BR /&gt;
&lt;DATESTAMP&gt; aaCalibration&lt;BR /&gt;
..&lt;BR /&gt;
.... events during “aaCalibration” phase, all with datestamp&lt;BR /&gt;
...&lt;BR /&gt;
&lt;DATESTAMP&gt; aaInfo&lt;BR /&gt;
...&lt;BR /&gt;
... events during “aaInfo” phase&lt;BR /&gt;
...&lt;BR /&gt;
&lt;DATESTAMP&gt; aaMarks&lt;BR /&gt;
...&lt;BR /&gt;
... events during “aaMarks” phase, all with datestamp&lt;BR /&gt;
...&lt;/DATESTAMP&gt;&lt;/DATESTAMP&gt;&lt;/DATESTAMP&gt;&lt;/DATESTAMP&gt;&lt;/P&gt;

&lt;P&gt;When I search with this:&lt;BR /&gt;
host=hostA sourcetype="typeB" earliest="05/02/2014:00:00:00" latest="05/03/2014:00:00:00" | transaction name=aaRegistration&lt;/P&gt;

&lt;P&gt;The result does show the one event that starts the transaction. But I do not get any of the events between the start and the end, just a single event.&lt;/P&gt;

&lt;P&gt;Question: what do I need to change to be able to see a list of &lt;EM&gt;all&lt;/EM&gt; events that occurred between the start and the end of the “aaRegistration” phase?&lt;/P&gt;

&lt;P&gt;Pointers appreciated. Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2014 14:59:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-not-providing-all-events-in-target-range/m-p/161498#M45674</guid>
      <dc:creator>jlacal</dc:creator>
      <dc:date>2014-07-29T14:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Transaction not providing all events in target range.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Transaction-not-providing-all-events-in-target-range/m-p/161499#M45675</link>
      <description>&lt;P&gt;Hello:&lt;BR /&gt;
Not really answering my own question but just posting this as it may be useful to others facing the same issue.&lt;/P&gt;

&lt;P&gt;"You have to have a common field to match on for the transaction command"&lt;BR /&gt;
From: &lt;A href="http://answers.splunk.com/answers/91742/grouping-of-similar-events"&gt;http://answers.splunk.com/answers/91742/grouping-of-similar-events&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;It looks like I may need to create a new field to use for the "transaction" to group on.&lt;BR /&gt;
Using my example above, I may need to add a new field (let's call it "phase_name") that  describes which "phase" of the program each event belongs to.&lt;/P&gt;

&lt;P&gt;For example:&lt;BR /&gt;
&lt;DATESTAMP&gt;  aaRegistration&lt;BR /&gt;
...&lt;BR /&gt;
... events during “aaRegistration” phase, all with datestamp&lt;BR /&gt;
...&lt;BR /&gt;
&lt;DATESTAMP&gt; aaCalibration&lt;/DATESTAMP&gt;&lt;/DATESTAMP&gt;&lt;/P&gt;

&lt;P&gt;I may need to add a new field where all events after&lt;BR /&gt;
&lt;DATESTAMP&gt;  aaRegistration&lt;BR /&gt;
have "phase_name" = "aaRegistration"&lt;/DATESTAMP&gt;&lt;/P&gt;

&lt;P&gt;Then I may (hopefully) be able to retrieve the "aaRegistration" transaction by using the "phase_name" field.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jul 2014 15:40:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Transaction-not-providing-all-events-in-target-range/m-p/161499#M45675</guid>
      <dc:creator>jlacal</dc:creator>
      <dc:date>2014-07-30T15:40:23Z</dc:date>
    </item>
  </channel>
</rss>

