Splunk Search

How can you filter a transaction where at least one of the paired events matches the criteria?

jkimmel6
Explorer

I have a transaction that pairs events based on three fields. Is it possible to then filter the results so that it only shows the paired events if at least one of the events has the field ‘Type’ containing the character ‘X’?

0 Karma
1 Solution

xpac
SplunkTrust
SplunkTrust

Hey,

Sure you can. Transaction combines all events of a transaction into one event, so if you append a | search Type=*x* after the transaction, it should do what you want.

View solution in original post

0 Karma

xpac
SplunkTrust
SplunkTrust

Hey,

Sure you can. Transaction combines all events of a transaction into one event, so if you append a | search Type=*x* after the transaction, it should do what you want.

0 Karma

jkimmel6
Explorer

Perfect, thanks.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...