Splunk Search
Highlighted

How to create a visualization showing event counts since beginning of the transaction, separated by time?

New Member

I have transactions with varying number of events. I want a plot showing how many events occur in buckets since the beginning of the transaction, e.g. how many events in the first 5 seconds, next 5 seconds, etc.

How can I do this?

0 Karma
Highlighted

Re: How to create a visualization showing event counts since beginning of the transaction, separated by time?

Legend

Lets assume you transactions are grouped by a txn_id. See if this is what you're looking for...

index=foo sourcetype=bar | bin span=5s _time | stats count by txn_id _time
0 Karma
Highlighted

Re: How to create a visualization showing event counts since beginning of the transaction, separated by time?

New Member

thanks sundareshr, it doesn't quite work, there are many transactions starting at different times

0 Karma