...iped them into transaction. The maxspan is 130m because the test transaction takes about 123m to complete.
(DXI OR sendMessage) 652F5692-5F3F-3434-F47B-180BA1CBDDEF | rename CORRELATIONID as msgid | transact...
...t;.*)\" bytes read (?<sftp_bytes_read>\d+)" If I wanted to see how much data was downloaded (without caring about which user) I would just do a timechart which does the trick: appname=s...
...poch time format) | eval _time=actionTimeStamp | sort 0 -actionTimeStamp | transaction SID startswith=(actionId="1") endswith=(actionId="6")
I get a different number of transactions. It seems l...
Hey,
I have a question about the transaction search command.
If I am using a transaction on an event that has two timestamps in it, how can I access/use both of the timestamps after the transact...
Hi all,
Hoping someone can give some pointers how to solve this problem:
I run a transaction command on the last two weeks, which gives about 20.000 events, and for about 85 percent of e...
Im very new to splunk. Could anyone please help me with the following issue?
I am in need to collect the details about the user for the Success Login attempts.
These success login attempts e...
...n a transaction with ProjectID. No problems there. My issue is that I want to incorporate the error message in the transaction but adding the MessageID like this | transaction ProjectId, MessageID d...
Hi all,
I try to group events using transaction. Since there are multiple endswith condition, i tried following to match either one of the 3 string patterns but unable to match:
... | transact...
Due to various cross references, I am forced to use nested transactions. In other words, I group several events into a transaction, and then I group several of those transactions in yet another transact...