Splunk Search

how to group by transaction type

avikc100
Path Finder

My Log data looks like:

avikc100_0-1717438117378.png

i am using this query:

index="webmethods_prd" source="/apps/WebMethods/IntegrationServer/instances/default/logs/CXMLOrders.log" |eval timestamp=strftime(_time, "%F") | chart limit=30 count as count over TransactionType by timestamp

 

I have to built report on transaction type, total count date wise

 

avikc100_2-1717438485508.png

 

please help to form the query,

due to space it is not showing properly

TransactionType = cXML OrderRequest

TransactionType = cXML ConfirmationRequest

 

 

Regards

Avik

 

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I presume the problem is the table is very wide.  If so, try swapping the terms in the chart command

index="webmethods_prd" source="/apps/WebMethods/IntegrationServer/instances/default/logs/CXMLOrders.log" 
| eval timestamp=strftime(_time, "%F") 
| chart limit=30 count as count over timestamp by TransactionType

Alternatively, try the timechart command.

index="webmethods_prd" source="/apps/WebMethods/IntegrationServer/instances/default/logs/CXMLOrders.log" 
| eval timestamp=strftime(_time, "%F") 
| timechart useother=0 limit=30 count by TransactionType

 

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...