Splunk Search

how to reverse the data in transaction ?

graju89
Path Finder

Hi, I have some issue with transaction command. It works fine. but sometimes endswith pattern appear and startswith pattern in the log. So the transcation command failing to convert that as a transaction.

For example,
Works fine for below log,
XXXXXXXXXend
XXXXXXXXXstart
Occassionally the data reverses like below and trasnaction command doesnt find it
XXXXXXXXXstart
XXXXXXXXXend

Is there a wrok around for this?

0 Karma

PavelP
Motivator

Hello @graju89,

I haven't any good solution for you, so may be just use an ineffective way of appending two searches:

search ... |transaction startswith="start" endswith="end"  maxspan=10s|sort 0 - _time| fields action duration | append [search ... |transaction startswith="end" endswith="start"  maxspan=10s]
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...