Splunk Search

With the transaction command, how do I get the duration between the first startswith to the last endswith?

xindeNokia
Path Finder

query like below:

| transaction startswith="Init" endswith="FINISHED" by ip
| table duration ip

Each IP has multiple "init" and "finish". Is there a way to group the first "init" to the last "Finished" instead of grouping the closest two?

Thanks in advance!

0 Karma
1 Solution

renjith_nair
SplunkTrust
SplunkTrust

@xindeNokia,

Try stats

"your search"  "init" OR "finished" |stats earliest(_time) as first,latest(_time) as last by ip|eval duration=last-first

View solution in original post

0 Karma

renjith_nair
SplunkTrust
SplunkTrust

@xindeNokia,

Try stats

"your search"  "init" OR "finished" |stats earliest(_time) as first,latest(_time) as last by ip|eval duration=last-first

View solution in original post

0 Karma

xindeNokia
Path Finder

it works, thank you very much! much appreciated!

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!