Splunk Search

How to create eventtype on transaction

nikunj_mochi
New Member

Hi Team,

I am creating a pie chart based on eventtype. For my one of the application logs, I have two logs for one unique request. So, I have used transaction to find out duration, but now the problem is I can't create eventtype on transaction. Could you please suggest an alternate?

Please let me know if any further detail required.
I have search like below on which I want to create an eventtype:

host="prod-ep-*"    | transaction GUID,Thread_Name,transType maxevents=2 

Thanks
Nikunj

0 Karma

sjohnson_splunk
Splunk Employee
Splunk Employee

Do you already have an eventtype for one of the events in the transaction? I think that should be carried over into the resulting transaction . Maybe something as simple as basing it off of the sourcetype of one of the events.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Can you provide sample data of the logs as well as how you're extracting each sourcetype? (inputs, props, & transforms if applicable)

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...