Splunk Search

Why is the transaction command not working?

ramprakash
Explorer

Hello Everyone...I have the below query and I want to evict transactions that starts with Message arrived but not ending with "ml-ok-to-commit[yes]". With keepevicted command, I am not getting the correct result.

Can someone please confirm where am i lacking ?

index=sara_listener* "INF" source="/sara2001/demi/log/listener-mq-swift-mx-ordr-*-mq-swift-mx-ordr-*.log*" | rex field=source "/sara2001/demi/log/listener-mq-swift-mx-ordr-(?<a_letter_a>.*)-mq-swift-mx-ordr-(?<a_letter>.*).log*"  | rex field=_raw "\[(?<ID>[^\]]*)"   | transaction source startswith="Message arrived" endswith="ml-ok-to-commit[yes]"  keepevicted=true |chart limit=0 count by date_hour
0 Karma

ccl0utier
Splunk Employee
Splunk Employee

Looking at the documentation for the transaction command, it looks like your events might not be marked as "evicted" based on matching a "startswith" message.

Ref: https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transaction

What incorrect results are you seeing?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...