We have our webservice logs on splunk having separate request (input) and response(output) log. There is one common unique id field between request and response log. But I want to match events in such a way to have count on basis of "requst_name" from request log and "response_cd" (where response_cd is not "00")from response log.
Example of request and response events:
RESPONSE EVENT :
(Response_cd may have different values)
I have tried transaction commond to group events and then search for non "00" response-cd but search is taking very long time.
Thanks in advance!