Splunk Search

How do I separate the results of a transaction to separately show each event?

Legend

Hi at all,

I have to separate the results of a transaction to separately show each event.
I'd like to do this because I have to aggregate events into a transaction to verify some rules (eventcount), but after, I'd like to separately show events.

How can I do this?
thank you.
Bye.
Giuseppe

1 Solution

SplunkTrust
SplunkTrust

Try this:

tag=SM 
| transaction sourcetype Application maxspan=300s mvraw=true
| eval myRaw = _raw
| mvexpand myRaw 
| rename myRaw as _raw

View solution in original post

Esteemed Legend

Don't use transaction in the first place.

0 Karma

SplunkTrust
SplunkTrust

Try this:

tag=SM 
| transaction sourcetype Application maxspan=300s mvraw=true
| eval myRaw = _raw
| mvexpand myRaw 
| rename myRaw as _raw

View solution in original post

Motivator

What is the query that you're using to generate the results?

0 Karma

Legend

It's a very simple search:
tag=SM | transaction sourcetype Application maxspan=300s

0 Karma