Splunk Commands : How "transaction" command works

แชร์
ฝัง
  • เผยแพร่เมื่อ 25 ต.ค. 2024

ความคิดเห็น • 19

  • @jotne
    @jotne 5 ปีที่แล้ว +5

    Hi. Thanks for another good video.
    There are two option in transaction that you should mention and do som explanation about.
    1. How to use startswith and endswith when dealing with field value. It can be used like this: startswith=(eventid=session.connect).
    2. The other one is more complicated. When using field in mvlist, like this: mvlist="time,message,eventid,status"

    • @splunk_ml
      @splunk_ml  5 ปีที่แล้ว

      Yep I missed that... Thanks for pointing it out.

    • @xaviercortez5625
      @xaviercortez5625 9 หลายเดือนก่อน

      I have to make note of this thanks.

  • @sumanthkumarchaganti9209
    @sumanthkumarchaganti9209 5 ปีที่แล้ว +1

    Very well illustrated about the topic and helped me to solve many queries, I have on using transaction command . Thank You . Looking forward for more videos on splunk .

    • @splunk_ml
      @splunk_ml  5 ปีที่แล้ว

      Thanks Sumanth.

  • @basudevpradhan8043
    @basudevpradhan8043 5 ปีที่แล้ว

    Thanks for the detailed illustration of transaction command in splunk.

  • @__goyal__
    @__goyal__ 3 ปีที่แล้ว

    Thank you Sid! Absolutely loved the explanation!!

  • @AbhishekVerma-hx8bq
    @AbhishekVerma-hx8bq 5 ปีที่แล้ว +1

    Very well explained, Thank you so much and please keep sharing such videos, please share some videos on orphan alerts and Dashboards

    • @splunk_ml
      @splunk_ml  5 ปีที่แล้ว

      Thanks Abhishek. I already created some video on dashboards , in future I will create more.

  • @Sugreev916
    @Sugreev916 5 ปีที่แล้ว +1

    Great Explanation as usual Thanks Sir !!! Can you put a small video on internal index and internal fields.

    • @splunk_ml
      @splunk_ml  5 ปีที่แล้ว +1

      Thanks....sure

  • @christojojo6590
    @christojojo6590 11 หลายเดือนก่อน

    what is keeporphan command?

  • @shenazgilani6370
    @shenazgilani6370 5 ปีที่แล้ว +1

    Hi ,
    Great video..
    Can you please make video on CIM Please..

    • @splunk_ml
      @splunk_ml  5 ปีที่แล้ว

      Sure..But it may take some time as I have decent backlog to complete

  • @mohan2002sg
    @mohan2002sg 5 ปีที่แล้ว +1

    nice videos.
    can you also create some videos on ES app please?

    • @splunk_ml
      @splunk_ml  5 ปีที่แล้ว

      Thanks man...Yes I will try to cover that but it may take some time as I have huge backlog now ☺️

  • @venky_1544
    @venky_1544 4 ปีที่แล้ว

    hi
    I have tried the same transaction command sourcetype = access_* | transaction JSESSIONID client startswith=view endswith=purchase is giving me zero events i I have also used double quotes for view and purchase but still not working can you let me know where I'm going wrong

    • @splunk_ml
      @splunk_ml  4 ปีที่แล้ว

      Hi Prasad,
      Have you indexed the correct data? Also can you check "sourcetype = access_*" this query is giving you result or not for the selected time range.

  • @rdstill
    @rdstill 2 ปีที่แล้ว

    How I long to find a Splunk instructor whose first language is English. It really slows my brain down and have to focus extra hard to decipher first the broken English then the material. Sigh.