Hello, If possible, I need help on getting a Percentage of Uptime for a Transaction overtime. I have a Search created that creates a Transaction, it's based on: startwith=Create endswith=C...
...est1" source="test2" run="test3"
| transaction source run startswith IN ("field1", "field2", "field3") endswith="status: PASS" Instead of using IN keyword for startswith, I want to use a csv l...
...nd finish times and a second to find and sum the data that was sent between those times. I am really struggling with the nested search aspect of this. I can get a transaction search to produce the s...
Whats the best way to summarize this data and subsequently search the results? The reason i ask is because the docs mention there is a transaction command that may need to be swapped for an si* c...
...ps_accessReqRejected)| timechart count by nps_callingStation
I use a similar query to find "AcceptedTrasnactions"
If opt to add appropriate code to transactions.conf, is there a way to gather stas based o...
...vents of varying line counts. index=honeypot sourcetype=honeypotLogs | transaction sessionID | search "SSH2_MSG_USERAUTH_FAILURE" OR "SSH2_MSG_USERAUTH_SUCCESS" Below is an example event. For...
for the search
index=* some_events | stats count
how to calculate the transaction per second for this search (how to get how many seconds for the search job)?
tried to use |addinfo | e...
Our office has a specific TRANSACTION search we do frequently to track all events related to a particular user. The search is always the same except for the user ID, which the Splunk user copies in f...
Hello,
Could someone explain me the following strange behavior with search
With this type of search :
sourcetype="cisco:esa:textmail" | transaction internal_message_id | search "M...