transaction

Any group of conceptually related events that spans time. Events grouped together by a transaction often represent a complex, multistep business-related activity, such as all events related to a single hotel customer reservation session, or a customer session on a retail website.

In Splunk, you can use the transaction command to group events from multiple applications, hosts, and sources. You can save the transactions you create as transaction types.

You can also configure transaction types directly through transactiontypes.conf.

Transactions are also a type of knowledge object.

For more information

From the Knowledge Manager Manual:

From the Search Reference:

From the Admin Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time