Splunk Search

Correlation Analysis Labs- How do I modify search to display the transactions in table?

Nadeem
New Member
index=web sourcetype=access_combined
| transaction _time,clientip, JSESSIONID,action



How do I Modify my search to display the transactions in a table for above SPL

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Nadeem,

I,'m not sure that you correlation runs, because using :time as key without a grouping using the bin  (or bucket9 command, it's diffoicoult that more events have the same timestamp.

And anyway, I wouldn't use transaction command because it's a very slow command, I'd use stats, something like this (e.g. grouping for the same hour);

index=web sourcetype=access_combined
| bin span=1h _time
| stats count BY _time clientip JSESSIONID action

this search is surely faster than the previous one.

Ciao.

Giuseppe

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

as other already said, 1st you must define what you want to be in your transaction?

Usually it contains events mapped by client and JSESSIONID like

index=web sourcetype=access_combined
| transaction startswith=<any start action for transaction> endswith=<end action for transaction> clientip JSESSIONID
| table _time JSESSIONID clientip action
| sort 0 _time

You could/should change those parameters for transaction command based on what you want to find.

Also using stats like @gcusello shows is one option, but as said, 1st you need to know what is your transaction.

r. Ismo 

yuanliu
SplunkTrust
SplunkTrust

Did you forget to tell us what you want the table to include?  Are you just looking for table?  For example, if you want fields a, b, c in addition to clientip, JSESSIONID,action, you can do

| table _time a b c clientip, JSESSIONID,action
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...