Splunk Search

How to find difference between events for a transaction?

marisstella
Explorer

Hello Everyone,
I want to find duration between the events in a transaction.
Let's say I have 100 events In a transaction, there is a failure at 49 th event and it is continued to 69th event so I want to calculate the difference between these two and find out how much time taken between these 20 events.
Can anyone of you help me on this?

0 Karma

to4kawa
Ultra Champion

for a transaction?
sorry, I don't use it.

your_search
| reverse
| streamstats count(searchmatch("failure"))) as session by your_transaction_id
| stats range(_time) as duration by your_transaciotn_id  session
| eval duration=tostring(duration,"duration")
0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...