Splunk Search

How to join 2 results and use transaction to display calls within a 3 second timespan for weblogic access logs?

edookati
Path Finder

in weblogic access log, i need to join 2 results and use transaction to display the calls within 3s timespan, but this doesn't work.
Can you please help me?

index=olb_logs sourcetype="access-API" URL="/bankapi/session" method=POST | join sessionID [Search URL="/bankapi/accounts" method=GET] | transaction sessionID maxspan=3s
Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Try this

index=olb_logs sourcetype="access-API" (URL="/bankapi/session" method=POST ) OR (URL="/bankapi/accounts" method=GET) | transaction sessionID maxspan=3s

View solution in original post

0 Karma

somesoni2
Revered Legend

Try this

index=olb_logs sourcetype="access-API" (URL="/bankapi/session" method=POST ) OR (URL="/bankapi/accounts" method=GET) | transaction sessionID maxspan=3s
0 Karma

somesoni2
Revered Legend

Try adding maxevents=2 in the transaction command.

0 Karma

edookati
Path Finder

Sorry, it is still giving me the same URLs in one transaction.

0 Karma

edookati
Path Finder

Thanks. this really helped. But, I am seeing same URLs in one transaction for most of the results and I want to display transaction results only if the URLs are different like the one below

2014-11-13 22:59:49 0.357 3152 2b76f0999150450e9b4a8c95e805ba41 - XXXXXX 00.00.00.00 00.00.00.00 00.00.00.00 00.00.00.00 GET /bankapi/ABCD 200 isExternal
2014-11-13 22:59:52 0.301 3152 2b76f0999150450e9b4a8c95e805ba41 - XXXXXX 00.00.00.00 00.00.00.00 00.00.00.00 00.00.00.00 GET /bankapi/EFGH 200 isExternal

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...