Search for overlapping transactions
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Contents
Search for overlapping transactions
Scenario
I have transactions where the unique key is client_id, transaction_id. Once these transactions are created, they are interested in finding overlaps in time - where one client_id launches multiple transactions at the same time. What would that search look like?
This documentation applies to the following versions of Splunk: 4.0 , 4.0.1 , 4.0.2 , 4.0.3 , 4.0.4 , 4.0.5 , 4.0.6 , 4.0.7 , 4.0.8 , 4.0.9 , 4.0.10 , 4.0.11 View the Article History for its revisions.