Hi,
Why do you filter the result of transaction command with duration=0?
I think that causes Splunk to return sessions that immediately end after they start.
Maybe "concurrency" command can be used for your purpose.
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Concurrency
... View more