Follow these steps to leverage summary indexing in calculating an hourly count of sessions versus the completed transactions:
- Log in to your Splunk server.
- Select the Operational Intelligence application.
- From the search bar, enter the following search and select to run over Last 60 Minutes:
index=main sourcetype=log4j | stats dc(sessionId) AS Sessions, count(eval(requestType="checkout")) AS Completed_Transactions
- Splunk should now display results similar to the following:
- Click on the Save As dropdown and select Report from the list:
- In the pop-up box that gets displayed, enter cp09_sessions_transactions_summary ...