I have a ticket dump with following fields.
Transaction ID
Transaction Type
Description
Priority
urgency
Created On
Created By
Actual Closed
Resolution code
SR Type
App ID
My need to correlate among 2 fields. Please do provide few correlation search commands(SPL) with above fields. Also need to convert the search into dashboards.
Hi @asm_coe,
Correlation takes place usually between multiple sources with similar fields. I think you're looking for building transactions. For that you can use the transaction
command.
Your SPL would look like this :
index= yourIndex sourcetype=yourSourcetype | transaction Transaction_ID App_ID
This will combine all fields with similar transaction ID and APP ID together.
Official documentation here for the latest version:
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transaction
Let me know if that helps.
Cheers,
David
Hi @asm_coe,
Correlation takes place usually between multiple sources with similar fields. I think you're looking for building transactions. For that you can use the transaction
command.
Your SPL would look like this :
index= yourIndex sourcetype=yourSourcetype | transaction Transaction_ID App_ID
This will combine all fields with similar transaction ID and APP ID together.
Official documentation here for the latest version:
https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Transaction
Let me know if that helps.
Cheers,
David
Thanks David for the quick help, Also please how can I convert this search into a dashboard. like chart or pie chart.
Ah, that's the easy part ^^ After running the search right next to the search button there is a "save as" button. Click that, select dashboard panel and then select either to make a new dashboard or an existing one.
If you need some documentation about that let me know !
Thanks David for your help. Really appreciated.
Most welcome ! Please upvote and accept the answer if it was helpful 🙂
You can do co-relation in multiple ways
index=yourIndex sourcetype=yourSourceType Priority>2 Transaction_ID="12345"
Please do read about converting searches to Dashboard
1. Build basic dashboard => http://dev.splunk.com/view/webframework-tutorials/SP-CAAAEN4
2. https://docs.splunk.com/Documentation/Splunk/latest/SearchTutorial/Createnewdashboard
Thanks Koshyk, Can you please suggest few correlation commands.