Splunk Search

how to reverse the data in transaction ?

graju89
Path Finder

Hi, I have some issue with transaction command. It works fine. but sometimes endswith pattern appear and startswith pattern in the log. So the transcation command failing to convert that as a transaction.

For example,
Works fine for below log,
XXXXXXXXXend
XXXXXXXXXstart
Occassionally the data reverses like below and trasnaction command doesnt find it
XXXXXXXXXstart
XXXXXXXXXend

Is there a wrok around for this?

0 Karma

PavelP
Motivator

Hello @graju89,

I haven't any good solution for you, so may be just use an ineffective way of appending two searches:

search ... |transaction startswith="start" endswith="end"  maxspan=10s|sort 0 - _time| fields action duration | append [search ... |transaction startswith="end" endswith="start"  maxspan=10s]
0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...