Splunk Search

is it possible to get the sum of a multivalued field within a transaction without a unique id??

vijai_thomas
Engager

Hi,
I want to count the number or errors within two keywords say starttran and endtran.
My log data would be like

  • starttran
  • tran Id:1000
  • error*
  • abc done
  • error*
  • endtran

My query : sourcetype="abc" | eval haserror=if(searchmatch("error"),1,0) | transaction startswith=starttran endswith=endtran mvlist=haserror | table haserror TRANID

O/P

  • haserror / TRANID
  • 0
  • 0 / 1000
  • 1
  • 0
  • 1
  • 0

But i want it like

  • haserror / TRANID
  • 2 / 1000

I tried using sum(haserror) by TRANID but din't. Kindly help . Also here can't TRANID be used as unique ID ?

Thanks a lot

Tags (2)
0 Karma
1 Solution

lguinn2
Legend
sourcetype="abc" 
| eval haserror=if(searchmatch("error"),1,0) 
| transaction startswith=starttran endswith=endtran mvlist=haserror 
| eval ErrorCount = mvcount(mvfilter(haserror==1))
| table ErrorCount TRANID

should work

View solution in original post

lguinn2
Legend
sourcetype="abc" 
| eval haserror=if(searchmatch("error"),1,0) 
| transaction startswith=starttran endswith=endtran mvlist=haserror 
| eval ErrorCount = mvcount(mvfilter(haserror==1))
| table ErrorCount TRANID

should work

vijai_thomas
Engager

This worked .. Thanks a lot 🙂

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...