Splunk Search

With the transaction command, how do I get the duration between the first startswith to the last endswith?

Path Finder

query like below:

| transaction startswith="Init" endswith="FINISHED" by ip
| table duration ip

Each IP has multiple "init" and "finish". Is there a way to group the first "init" to the last "Finished" instead of grouping the closest two?

Thanks in advance!

0 Karma
1 Solution

SplunkTrust
SplunkTrust

@xindeNokia,

Try stats

"your search"  "init" OR "finished" |stats earliest(_time) as first,latest(_time) as last by ip|eval duration=last-first

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

@xindeNokia,

Try stats

"your search"  "init" OR "finished" |stats earliest(_time) as first,latest(_time) as last by ip|eval duration=last-first

View solution in original post

0 Karma

Path Finder

it works, thank you very much! much appreciated!

0 Karma