Splunk Search

Extract InProgress Transaction

manvi_spl8
New Member

I want to filter out transactions(where status ="InProgress ") that started in the previous slot and those completed in the next slot. basically if earliest=04/27/2021:12:0:0 and latest=04/28/2021:12:0:0 I want to display only those transactions which started in the specified period and are in completed status.

I have a previous query like this :

stats earliest(_time) as InTime ,latest(_time) as OutTime,

values(eval(if(code="E100" OR code="E101" OR code="E102"))) as error,

count(eval(code="E010")) as messageReceived, count(eval(code="E030" OR code="E031")) as messageCompleted | sort - InTime

Labels (2)
Tags (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What defines a transaction? Do all the events for a transaction have the same unique correlation id?

0 Karma

manvi_spl8
New Member

All the transactions have unique Id

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Assuming code=E010 is your start and either E101 or E102 is your end, gather all the codes for the transaction on each event and then search for the events which have E010 and either E101 or E102, then calculate your stats from these events.

| eventstats values(code) as allcodes by transactionid
| search allcodes="E010" (allcodes="E030" OR allcodes="E031")
| stats earliest(_time) as InTime ,latest(_time) as OutTime,
values(eval(if(code="E100" OR code="E101" OR code="E102"))) as error,
count(eval(code="E010")) as messageReceived, count(eval(code="E030" OR code="E031")) as messageCompleted | sort - InTime
0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...