Hi,
If a transaction starts before a search interval, but finishes within it, is it included in the search? Also, if a transaction begins within the search interval but ends after it, how is that handled?.
If we wont get the before and after the search interval events, how to exclude/Include those events in the results
Please help me to do this
Thanks & Regards
Read the documentation and pay special attention to evicted events (you have some control over what is/not included):
http://docs.splunk.com/Documentation/Splunk/6.3.0/SearchReference/transaction
Read the documentation and pay special attention to evicted events (you have some control over what is/not included):
http://docs.splunk.com/Documentation/Splunk/6.3.0/SearchReference/transaction