Splunk Search
Highlighted

transaction question

Explorer

I use the code below, and it works..

sourcetype="splunkpagerequest" | transaction session_id maxspan=3s

and I want to use the code below

sourcetype="splunkpagerequest" | transaction requesturi AND sessionid maxspan=3s

it works?
please explain how to work the upper code..

actually, I want the result below

if below
requesturi=1 sessionid=a time=2013/07/10 12:00:00
requesturi=2 sessionid=a time=2013/07/10 12:00:02

count is 2

if below
requesturi=1 sessionid=a time=2013/07/10 12:00:00
requesturi=1 sessionid=a time=2013/07/10 12:00:02

count is 1

someone please help me..

Tags (1)
0 Karma
Highlighted

Re: transaction question

Champion

sourcetype="splunkpagerequest" | transaction requesturi sessionid maxspan=3s

View solution in original post

Highlighted

Re: transaction question

Explorer

Thank you so much!!

0 Karma