Splunk Search

Transaction command: How to get the pair up multiple "startswith", but single "endswith" events?

koshyk
Super Champion

hi
We have events something like below

2019-04-30 11:00:01 page=Login.jsp action=login  userid=1234 comment="User opened a session"
2019-04-30 11:01:01 page=Login.jsp action=login  userid=1234 comment="User might have opened another session"
2019-04-30 11:02:01 page=Logout.jsp action=logout userid=1234 comment="User logged out session"

But when user "logsout", that means he has completely logged out of all sessions

When I do a

...
| transaction userid startswith=(action="login") endswith=(action="logout") maxspan=1h keepevicted=true

I was looking for output as a Single Transaction, but currently it comes up as "TWO" txn events; as it pairs the closest/nearby events ONLY

# Transaction Output1
2019-04-30 11:01:01 page=Login.jsp action=login  userid=1234 comment="User might have opened another session"
2019-04-30 11:02:01 page=Logout.jsp action=logout userid=1234 comment="User logged out session"

# Transaction Output2
2019-04-30 11:00:01 page=Login.jsp action=login  userid=1234 comment="User opened a session"

Any options to make it as "SINGLE" output? as the user have logged out of system, so pairing with above conditions should pair both "logins" to a single logout

I was looking for OUPUT like below

# Single Transaction Output
2019-04-30 11:00:01 page=Login.jsp action=login  userid=1234 comment="User opened a session"
2019-04-30 11:01:01 page=Login.jsp action=login  userid=1234 comment="User might have opened another session"
2019-04-30 11:02:01 page=Logout.jsp action=logout userid=1234 comment="User logged out session"
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...