Consider the following search:
index=web sourcetype=access_corabined
The log shows several events that share the same jsesszonid value (SD462K101O2F267). View the events as a group.
From the following list, which search groups events by jSSESSIONID?
The transaction command groups events that share a common value in a specified field, such as JSESSIONID, and that occur within a specified time range. The search command filters the results to show only the events that match the given value of JSESSIONID.This search groups the events by JSESSIONID and then shows only the events that have the value SD462K101C2F267 for JSESSIONID2
1: Splunk Core Certified Power User Track, page 9.2: Splunk Documentation, transaction command.
Limited Time Offer
25%
Off
Nu
3 months agoDesirae
3 months agoLou
3 months agoKimbery
4 months agoTheron
4 months agoLuann
4 months agoMartin
4 months agoNohemi
4 months agoTrinidad
5 months agoLeonida
5 months agoElenor
5 months agoRoosevelt
5 months agoKanisha
5 months agoElbert
5 months agoJanet
5 months agoHeike
5 months agoJarvis
5 months agoWillie
5 months ago