Splunk Search

How do you reference the value of a transaction

adylent
Path Finder

Does anyone know if it is possible to reference the value of a transaction?

For instance

transaction account  startswith="event_type=login" endswith="event_type=logout" 

At this point I should have events encapsulating full user sessions (per account). Can I reference the value of a transaction?

Ideally I'd like to do something like

rex field=transaction mode=sed "s/oldvalue/newvalue/g"  

without have to do this on the _raw prior to the transaction.

Thanks greatly

0 Karma
1 Solution

kristian_kolb
Ultra Champion

After the transaction command, all events that make up the transaction are stored in the _raw field. The old _raw is gone. Of course, events are only changed for the duration of the search - and not changed on disk.

Try it out, just as you wrote it, but remove the field=transaction part.

... | transaction account  startswith="event_type=login" endswith="event_type=logout" 
| rex mode=sed "s/oldvalue/newvalue/g"

/k

View solution in original post

kristian_kolb
Ultra Champion

After the transaction command, all events that make up the transaction are stored in the _raw field. The old _raw is gone. Of course, events are only changed for the duration of the search - and not changed on disk.

Try it out, just as you wrote it, but remove the field=transaction part.

... | transaction account  startswith="event_type=login" endswith="event_type=logout" 
| rex mode=sed "s/oldvalue/newvalue/g"

/k

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...