I am trying to get the transaction results from a lookup file and I have _time field written into it for this to work. The duration condition seems to be working, but the query stops working the moment I add maxpause condition to it. Below is the query I am currently trying to fix.
Please help me here.
| inputlookup LOOKUP.csv
| eval durationLimitInSeconds=durationLimitInMinutes*60
| eval now=now()
| eval temp=(now-(2*60*60)-120)
| where _time>temp
| transaction maxpause=10s code
| where eventcount>2 AND duration>durationLimitInSeconds
| fields _time code duration durationLimitInSeconds eventcount
Below is the sample data, if it helps. I want events with pause more than a few seconds (10s) to be considered as a different transaction, but the query I use treats all of them as single event and if I include maxpause, the query doesn't work at all.
_time duration_measure code loglevel durationLimitInMinutes
2017-03-17 00:25:48 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:25:46 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:25:41 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:25:21 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:25:21 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:25:11 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:25:11 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:25:00 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:24:46 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:24:46 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:24:41 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:24:41 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:24:27 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:24:27 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:24:06 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:24:06 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:24:00 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:24:00 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:24:00 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:23:48 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:23:48 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:23:48 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:23:45 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:23:45 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:23:41 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:23:41 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:23:22 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:23:06 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:22:46 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:22:41 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:22:22 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:22:22 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:22:06 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:22:06 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:22:00 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:22:00 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:21:48 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:21:48 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:21:46 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:21:41 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:21:22 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:21:06 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:21:00 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:21:00 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:20:55 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:20:55 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:20:46 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:20:46 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:20:46 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:20:41 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:20:41 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:20:41 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:20:22 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:20:22 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:20:06 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:20:06 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:20:00 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-17 00:19:48 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-16 23:59:22 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-16 23:59:09 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-16 23:59:06 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-16 23:58:57 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-16 23:58:55 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-16 23:58:41 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-16 23:49:12 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-16 23:49:09 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-16 23:49:09 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
2017-03-16 23:49:06 m EVENTAPI_FAILED_PROPORTION_ERROR ERROR 10
... View more