Splunk Search

how to group by transaction type

avikc100
Path Finder

My Log data looks like:

avikc100_0-1717438117378.png

i am using this query:

index="webmethods_prd" source="/apps/WebMethods/IntegrationServer/instances/default/logs/CXMLOrders.log" |eval timestamp=strftime(_time, "%F") | chart limit=30 count as count over TransactionType by timestamp

 

I have to built report on transaction type, total count date wise

 

avikc100_2-1717438485508.png

 

please help to form the query,

due to space it is not showing properly

TransactionType = cXML OrderRequest

TransactionType = cXML ConfirmationRequest

 

 

Regards

Avik

 

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I presume the problem is the table is very wide.  If so, try swapping the terms in the chart command

index="webmethods_prd" source="/apps/WebMethods/IntegrationServer/instances/default/logs/CXMLOrders.log" 
| eval timestamp=strftime(_time, "%F") 
| chart limit=30 count as count over timestamp by TransactionType

Alternatively, try the timechart command.

index="webmethods_prd" source="/apps/WebMethods/IntegrationServer/instances/default/logs/CXMLOrders.log" 
| eval timestamp=strftime(_time, "%F") 
| timechart useother=0 limit=30 count by TransactionType

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...