Hi,
We are trying to set up an alert which will trigger every time a particular transaction is completed. The alert will send out an email including the duration of that transaction and the sourcetype. What is the simplest way to achieve the above?
Thanks in Advance
Try something like this
index=* [search index=* earliest=-5m@m status=transactioncomplete | stats count txnId | fields - count] | transaction txnId startswith="status=transactionstart" endswith="status=transactionend" keepevicted=false | table txnId duration
Setup alert based on the results.
I am trying this, but everytime I am getting an error saying the txnId field is invalid in the stats section.