Splunk Search

Is there a way to ignore single events in (transaction)?

albyva
Communicator

I'm using (transaction) to count the number of events in a stream of data.
There are numerous single events, but I'm only interested in events that are 2 or more.
Using the string maxevent=X, I can limit the maximum number of events within a given time span,
but can you ignore a number of events less than a given number (ie: minevents=2)???

index=generic | transaction data maxevents=2 maxspan=2m

Tags (2)
0 Karma
1 Solution

somesoni2
Revered Legend

Any transaction command adds fields like duration and eventcount. You can filter based on field eventcount.

index=generic | transaction data maxspan=2m | where eventcount > 1

View solution in original post

somesoni2
Revered Legend

Any transaction command adds fields like duration and eventcount. You can filter based on field eventcount.

index=generic | transaction data maxspan=2m | where eventcount > 1

albyva
Communicator

Good idea. Thanks. 🙂

0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...