Splunk Search

How to create eventtype on transaction

nikunj_mochi
New Member

Hi Team,

I am creating a pie chart based on eventtype. For my one of the application logs, I have two logs for one unique request. So, I have used transaction to find out duration, but now the problem is I can't create eventtype on transaction. Could you please suggest an alternate?

Please let me know if any further detail required.
I have search like below on which I want to create an eventtype:

host="prod-ep-*"    | transaction GUID,Thread_Name,transType maxevents=2 

Thanks
Nikunj

0 Karma

sjohnson_splunk
Splunk Employee
Splunk Employee

Do you already have an eventtype for one of the events in the transaction? I think that should be carried over into the resulting transaction . Maybe something as simple as basing it off of the sourcetype of one of the events.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Can you provide sample data of the logs as well as how you're extracting each sourcetype? (inputs, props, & transforms if applicable)

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...