I am using the transaction command to identify if a report runs over a certain time. Below is my search:
| transaction startswith="Start" endswith="Finish" keeporphans=true
| where _txn_orphan=1
This primarily is working except there seem to be some false positives. If a report runs and finishes within the same second (which happens if a user forgets a parameter) Splunk is still counting it as orphaned, so _txn_orphan is still 1 but it should be 0 since it actually completed. Has anyone run into this and have a better way or workaround for this?
Hi @aohls,
You can easily get rid of this by adding to your condition a minimum duration for the transaction. That way all those noisy transaction won't show anymore 🙂
Cheers,
David