There's more...

The transaction command provides many parameters to control the way in which transactions are grouped. Using the startswith and endswith parameters, you can control what marks the start and end of a transaction based on data inside the events. Using the maxspan, maxpause, or maxevents parameters, you can control the constraints around how long a transaction will be, the amount of time between events before splitting it into a new transaction, or the total number of events within a transaction.

Where possible, using the parameters available for the transaction command is highly encouraged. Using the transaction command without any other parameter can result in a processing intensive (and inefficient) search that takes a while ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.