Splunk Search

Is it possible to limit the transaction?

moinyuso96
Path Finder

After using transactions my "raw" field looks something like this. I want to limit the amount of rows captured  by transaction to be not more than 2? 

Is there anyway I can add to my query now 

| transaction startswith=TestResult="Start"

raw

4015_ABCD, Start, 8/11/2020 5:37:10 PM, 12345

4015_ABCD, Complete, 8/11/2020 5:37:30 PM, 12345

4015_ABCD, Start, 8/12/2020 10:23:34 AM, 12345

1113_EFGH, Start, 8/12/2020 12:00:00 PM, 67890

1113_EFGH, Complete, 8/12/2020 1:00:00 PM, 67890

1119_EFGH, Complete, 8/12/2020 2:00:00 PM, 67890

Labels (2)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @moinyuso96,

as you can see in the documentation (https://docs.splunk.com/Documentation/Splunk/8.2.0/SearchReference/Transaction), it's possible to define the maximum number of events to correlate using "maxevents" option.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @moinyuso96,

as you can see in the documentation (https://docs.splunk.com/Documentation/Splunk/8.2.0/SearchReference/Transaction), it's possible to define the maximum number of events to correlate using "maxevents" option.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...