New to splunk, using version 4.2.3
Imported some zipped log files into splunk. I can search them just fine, but the transaction command doesn't work as expected. Using the transaction command to find the duration of connections.
The search being run is -
index=myIndex | search * | transaction myId maxspan=30m startswith="MsgNo=0" endswith="Hang up"
The results however are not accurate, I have results where the myId pulled for startswith is different from the myId field pulled for endswith.
However, if I import the data into splunk's default index the above search works as expected.
How can I fix this without re-importing all the logs into the default index?
asked 09 Sep '11, 08:26