Splunk Search

how to reverse the data in transaction ?

graju89
Path Finder

Hi, I have some issue with transaction command. It works fine. but sometimes endswith pattern appear and startswith pattern in the log. So the transcation command failing to convert that as a transaction.

For example,
Works fine for below log,
XXXXXXXXXend
XXXXXXXXXstart
Occassionally the data reverses like below and trasnaction command doesnt find it
XXXXXXXXXstart
XXXXXXXXXend

Is there a wrok around for this?

0 Karma

PavelP
Motivator

Hello @graju89,

I haven't any good solution for you, so may be just use an ineffective way of appending two searches:

search ... |transaction startswith="start" endswith="end"  maxspan=10s|sort 0 - _time| fields action duration | append [search ... |transaction startswith="end" endswith="start"  maxspan=10s]
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...