Splunk Search

How to join 2 results and use transaction to display calls within a 3 second timespan for weblogic access logs?

edookati
Path Finder

in weblogic access log, i need to join 2 results and use transaction to display the calls within 3s timespan, but this doesn't work.
Can you please help me?

index=olb_logs sourcetype="access-API" URL="/bankapi/session" method=POST | join sessionID [Search URL="/bankapi/accounts" method=GET] | transaction sessionID maxspan=3s
Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Try this

index=olb_logs sourcetype="access-API" (URL="/bankapi/session" method=POST ) OR (URL="/bankapi/accounts" method=GET) | transaction sessionID maxspan=3s

View solution in original post

0 Karma

somesoni2
Revered Legend

Try this

index=olb_logs sourcetype="access-API" (URL="/bankapi/session" method=POST ) OR (URL="/bankapi/accounts" method=GET) | transaction sessionID maxspan=3s
0 Karma

somesoni2
Revered Legend

Try adding maxevents=2 in the transaction command.

0 Karma

edookati
Path Finder

Sorry, it is still giving me the same URLs in one transaction.

0 Karma

edookati
Path Finder

Thanks. this really helped. But, I am seeing same URLs in one transaction for most of the results and I want to display transaction results only if the URLs are different like the one below

2014-11-13 22:59:49 0.357 3152 2b76f0999150450e9b4a8c95e805ba41 - XXXXXX 00.00.00.00 00.00.00.00 00.00.00.00 00.00.00.00 GET /bankapi/ABCD 200 isExternal
2014-11-13 22:59:52 0.301 3152 2b76f0999150450e9b4a8c95e805ba41 - XXXXXX 00.00.00.00 00.00.00.00 00.00.00.00 00.00.00.00 GET /bankapi/EFGH 200 isExternal

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...