Splunk Search

How to create eventtype on transaction

nikunj_mochi
New Member

Hi Team,

I am creating a pie chart based on eventtype. For my one of the application logs, I have two logs for one unique request. So, I have used transaction to find out duration, but now the problem is I can't create eventtype on transaction. Could you please suggest an alternate?

Please let me know if any further detail required.
I have search like below on which I want to create an eventtype:

host="prod-ep-*"    | transaction GUID,Thread_Name,transType maxevents=2 

Thanks
Nikunj

0 Karma

sjohnson_splunk
Splunk Employee
Splunk Employee

Do you already have an eventtype for one of the events in the transaction? I think that should be carried over into the resulting transaction . Maybe something as simple as basing it off of the sourcetype of one of the events.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Can you provide sample data of the logs as well as how you're extracting each sourcetype? (inputs, props, & transforms if applicable)

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...