Transaction

The transaction command is used to find and group together related events that meet various criteria. Here are some of the things you can use the transaction command to do:

  • Group events together using a field value, such as an ID or IP address.
  • Group events that begin and end with specific field values.
  • Break up groups of events that span longer than a given duration. For example, if a transaction does not explicitly end with a message, you can specify a maximum span of time after the start of a transaction to mark the end of the group of events for that transaction.
  • To display raw event data for grouped events.

Some of the most common transaction arguments include:

  • <field-list>: Field name(s) used to group events into transactions ...

Get Splunk 7.x Quick Start Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.