Consider the following search:
index=web sourcetype=access_corabined
The log shows several events that share the same jsesszonid value (SD462K101O2F267). View the events as a group.
From the following list, which search groups events by jSSESSIONID?
The transaction command groups events that share a common value in a specified field, such as JSESSIONID, and that occur within a specified time range. The search command filters the results to show only the events that match the given value of JSESSIONID.This search groups the events by JSESSIONID and then shows only the events that have the value SD462K101C2F267 for JSESSIONID2
1: Splunk Core Certified Power User Track, page 9.2: Splunk Documentation, transaction command.
Limited Time Offer
25%
Off
Keena
5 months agoMozell
5 months agoCarlene
5 months agoKeena
5 months agoCarlene
5 months agoTwana
5 months agoBrynn
6 months agoAnnice
6 months agoBrynn
6 months agoAnnice
7 months ago