Splunk Search

Goal Funnel Analysis in Splunk

fitzgeraldsteel
Engager

How would I query for transactions that first went to page A, and then page B?

For one use case, I'm looking at goal funnels. Goal funnel visualization is a common web traffic analysis, where you look at the percentage of visitors that follow a predefined set of steps. For example, I've got a shopping cart: of the 100% of visitors that enter the site, 30% put something in their shopping cart, 7% start the checkout, and 2% complete checkout.

I see how I can use splunk to examine the weblogs, and group discrete events into transactions. But is there a way to calculate the goal funnel percentages from those transactions?

sideview
SplunkTrust
SplunkTrust

Sure. Let me kind of manufacture some details. If I'm way off base this might not be useful but it's worth a shot.

Starting point is some transaction like this:

<your search> | stats values(url) as urls by sessionId

(Often people start with transaction but stats is easier once you get used to being specific about what you need. )

From that point you can do the following. There's quite possibly a more elegant way to to this but this is the way that springs to mind::

<your search> | stats values(url) as urls by sessionId | eval added_to_cart=if(searchmatch("url=*/cart"),1,null()) | eval started_checkout=if(searchmatch("url=*/checkout"),1,null()) | eval completed_checkout=if(searchmatch("url=*/checkout_complete"),1,null()) | stats count count(added_to_cart) as step1 count(started_checkout) as step2 count(completed_checkout) as step3

and from there making percentages is just a little bit more eval but I think you see the idea. Hope this helps a bit.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...