Identifying and grouping transactions

Single events can be easily interpreted and understood, but these single events are often part of a series of events, where the event might be influenced by preceding events or might affect other events to come. By leveraging Splunk's ability to group associated events into transactions based on field values, the data can be presented in a way that allows the reader to understand the full context of an event and what led up to this point. Building transactions can also be useful when needing to understand the time duration between the start and finish of specific events, or calculating values within a given transaction and comparing them to the values of others.

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.