Splunk Search

timechart span and transaction rollover into hour (what happens to the duration of the transaction?)

cmisztur
Explorer

below example sums the duration when a machine is not running.

 ... 
    | sort 0 - time 
    | transaction startswith=running="0" endswith=running="1" keeporphans=f keepevicted=f
    | timechart span=1h sum(duration)

first transaction of an hour:

alt text

what happens to a transaction that rolls over into the hour?
will it report against 13th hour because the transaction takes the first event's timestamp...

like this one:

alt text

thanks
/c

0 Karma

somesoni2
Revered Legend

The timestamp of the transaction would be considered as the start time of the transaction which is in 13th hour, so your transaction would be counted for 13th hour, even though it ended in 14th. What's your requirement here? Do you want it to be counted for both hours?

0 Karma

cmisztur
Explorer

Correct, should split the transaction and fit into the hour it belongs in. So 1m4s into 13th hour, 0m23s into 14th hour.

0 Karma

niketn
Legend

@cmisztur, yes transaction will pick earliest time as the _time. Are you trying to create a transaction without id?

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

cmisztur
Explorer

correct, no ID.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

I wasn't entirely clear on what OP is asking.. But perhaps using stats rather than transaction will give more flexibility

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...