Splunk Search

How to use 'AND' keyword in Transaction command

sasank
Explorer

Hi,

I want to use 'AND' keyword either in startsWith or in endsWith.

<<search>> | transaction startsWith="some text" AND "some other text" endswith="some text" AND "some other text"

Is this possible?

 

Labels (1)
0 Karma

Manasa_401
Communicator

Hi @sasank 

According to the documentation, it is possible. Have a look at the below link.

https://docs.splunk.com/Documentation/Splunk/9.0.3/SearchReference/Transaction#Filter_string_options 

If this helps, karma would be appreciated.

Thanks,

Manasa

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...