Splunk Search

one to many transaction mapping

New Member

I am working for a product where my order will have multiple sub requests.
in one log i will have my main order number. once order is processed i will get sub request status with main order number as well.
Here i need to generate a report which contains duration between order submission and order processed at sub order level.
For example i have order abc, which has 5 sub requests.
My report should show
order suborder duration
abc 1 10
abc 2 4
abc 3 5

i tried , i am able to get the duration between main order submission and last sub request processed.

Tags (1)
0 Karma