Splunk Search

Extract InProgress Transaction

manvi_spl8
New Member

I want to filter out transactions(where status ="InProgress ") that started in the previous slot and those completed in the next slot. basically if earliest=04/27/2021:12:0:0 and latest=04/28/2021:12:0:0 I want to display only those transactions which started in the specified period and are in completed status.

I have a previous query like this :

stats earliest(_time) as InTime ,latest(_time) as OutTime,

values(eval(if(code="E100" OR code="E101" OR code="E102"))) as error,

count(eval(code="E010")) as messageReceived, count(eval(code="E030" OR code="E031")) as messageCompleted | sort - InTime

Labels (2)
Tags (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What defines a transaction? Do all the events for a transaction have the same unique correlation id?

0 Karma

manvi_spl8
New Member

All the transactions have unique Id

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming code=E010 is your start and either E101 or E102 is your end, gather all the codes for the transaction on each event and then search for the events which have E010 and either E101 or E102, then calculate your stats from these events.

| eventstats values(code) as allcodes by transactionid
| search allcodes="E010" (allcodes="E030" OR allcodes="E031")
| stats earliest(_time) as InTime ,latest(_time) as OutTime,
values(eval(if(code="E100" OR code="E101" OR code="E102"))) as error,
count(eval(code="E010")) as messageReceived, count(eval(code="E030" OR code="E031")) as messageCompleted | sort - InTime
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...