Splunk Search

Find recursive hierarchy in events without transaction

szk
New Member

Hello,
I have events that contain fields ID and parentID. By using those fields I would like to find all the events with selected ID and all the parents in hierarchy, so also parent of the parent etc. I know how to deal with the problem with transaction, however it takes a lot of time to finish, if the index has much data.
Is there any other way to deal with the problem?

Tags (1)
0 Karma

cmerriman
Super Champion

try using streamstats. I often avoid transaction with streamstats. you can't have a 'startswith'/'endswith', but there are helpful arguments. I've brought in the documentation.

http://docs.splunk.com/Documentation/Splunk/6.5.1/SearchReference/Streamstats

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...