Splunk Search

How to use transaction command with message and as argument?

abhi04
Communicator

How to use message name as argument for transaction command? I have logs relate to a particular message ID for one source type or an app say A but don't see any logs for the same message ID in another source type or app say B but when login to the server of app B,can see the logs related to app B.

Tags (1)
0 Karma

bangalorep
Communicator

Hello!
You could use something like this

| transaction message_id

Let me know if this works

0 Karma

p_gurav
Champion

Can you provide some sample data?

0 Karma

abhi04
Communicator

Sorry, I can't .

0 Karma

p_gurav
Champion

You can pass field name while doing transaction. Refer below doc :
https://docs.splunk.com/Documentation/Splunk/7.0.2/SearchReference/Transaction#Extended_Examples

ALso if data is not coming from app_B, can you run below command on server of appB:

.\splunk list monitor

And check data is being monitored or not?

0 Karma
Get Updates on the Splunk Community!

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...

Hunt Smarter, Not Harder: Discover New SPL “Recipes” in Our Threat Hunting Webinar

Are you ready to take your threat hunting skills to the next level? As Splunk community members, you know the ...