I have fetching data to Splunk from a transaction tracker table. My scenario is as given below.
Here is the example of the table data I fetch:
From the above data I need to find the count of transactions with status="Failed" and do not have any "Success" status. From the above example, I should get the result as 1, since transaction Id 1000 was successful in later stages.
Could you please advise.
Hi,
Can you try this if it helps?
...| stats values(Transation status) AS 'Status' values(Insert date time) AS Time BY "Transaction Id" | where Status="Failed"
HI @biju3705,
Can you please try this?
YOUR_SEARCH
| stats values(STATUS) as STATUS by TID
| where STATUS!="Success" AND STATUS="Failed"
Thanks