Splunk Search

Nested Transaction Time

vanaepi
Explorer

Due to various cross references, I am forced to use nested transactions. In other words, I group several events into a transaction, and then I group several of those transactions in yet another transaction. And it works the way I want it to, except...

The time of a transaction is the same as the time of the first event. So the duration of the last transaction is calculated as the difference between the starttime of the first transaction and the starttime of the last transaction.

In stead, I need the difference between the starttime of the first transaction and the endtime of the last transaction.

How would I go about doing this?

Tags (2)
1 Solution

kristian_kolb
Ultra Champion

Don't have a splunk in front of me right now, but I'm guessing something like this might work (adding the duration of the last sub-transaction to the duration of the 'parent')

... | transaction X | eventstats latest(duration) as latest_dur by X | transaction Y | eval dur = duration+latest_dur 

Hope this helps,

K

View solution in original post

kristian_kolb
Ultra Champion

Don't have a splunk in front of me right now, but I'm guessing something like this might work (adding the duration of the last sub-transaction to the duration of the 'parent')

... | transaction X | eventstats latest(duration) as latest_dur by X | transaction Y | eval dur = duration+latest_dur 

Hope this helps,

K

vanaepi
Explorer

Yep it did the trick. Thanks!

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...