Splunk Search

Searching by Transaction TYPE

mikefoti
Communicator

The following query finds what I would call "RejectedTrasnactions"

index="radius"  | transaction nps_Class maxspan=1s startswith=(eventtype=nps_accessRequested) endswith=(eventtype=nps_accessReqRejected)| timechart count by nps_callingStation

I use a similar query to find "AcceptedTrasnactions"

If opt to add appropriate code to transactions.conf, is there a way to gather stas based on transaction types? For example, would a query like this show me how many of each transaction type occurred per time period?

index="radius" |timechart count by transaction
Tags (2)
0 Karma
1 Solution

MarioM
Motivator

it's actually transactiontypes.conf but it only allow to call 1 transaction definition by using "... | transaction name=mytransactiondef ..." and this "name" field doesnot seems to be searchable.

Then i would try a different way either using summary indexing & marker or eval & case function

View solution in original post

0 Karma

MarioM
Motivator

it's actually transactiontypes.conf but it only allow to call 1 transaction definition by using "... | transaction name=mytransactiondef ..." and this "name" field doesnot seems to be searchable.

Then i would try a different way either using summary indexing & marker or eval & case function

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...