You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Splunk按UUID统计事务状态:COMPLETE/PENDING/ERROR实现方案咨询

Solution to Track Transaction Status by UUID in Splunk

Hey there! As a Splunk user who's built similar status-tracking dashboards, let me break down exactly how to implement this for your use case. We'll use Splunk's streamstats, eventstats, and eval commands—perfect for handling event ordering and conditional logic, even for beginners.

Step 1: Add Sequential Numbering to Events per UUID

First, we need to assign a unique number to each event under the same UUID so we can easily identify the 3rd event. Use streamstats to count events per UUID:

index=myindex OR index=myindex2 uuid=98as786-ffe6-4de1-929y-080e99bc2e6r (status="202") OR (TransactionStatus="PUBLISHED") 
| append [search index=myindex2 (logMessage="Producer created new event") event="delivered" OR event="processed" serviceName="abc" [search index=myindex uuid=98as786-ffe6-4de1-929y-080e99bc2e6r AND status="SUCCESS" AND serviceName="abc" | top limit=1 headerId | fields + headerId | rename headerId as message_id]]
# Add sequential numbering for events in each UUID group
| streamstats count as event_num by uuid

Step 2: Extract Key Metrics for Each UUID

Next, use eventstats to grab two critical pieces of information for every UUID:

  • Total number of events associated with the UUID
  • The event value of the 3rd event (if it exists)
| eventstats max(event_num) as total_events by uuid
| eventstats values(eval(if(event_num=3, event, null()))) as third_event by uuid

Step 3: Calculate Transaction Status with Conditional Logic

Use Splunk's case function inside eval to map your predefined rules to clear status labels:

| eval transaction_status=case(
    total_events=3 AND third_event="delivered", "COMPLETE",
    total_events>=3 AND third_event!="delivered", "PENDING",
    total_events<3, "ERROR"
)
  • COMPLETE: Exactly 3 events exist, and the 3rd event has event="delivered"
  • PENDING: 3 or more events exist, but the 3rd event isn't "delivered"
  • ERROR: Fewer than 3 events exist (so no 3rd event at all)

Step 4: Deduplicate & Count Statuses per UUID

Since each UUID will have multiple events, we need to keep only one entry per UUID (with its assigned status), then count how many UUIDs fall into each status category:

| dedup uuid transaction_status
| stats count as "UUID Count" by transaction_status

Full Combined Query

Here's the complete query you can plug directly into your dashboard:

index=myindex OR index=myindex2 uuid=98as786-ffe6-4de1-929y-080e99bc2e6r (status="202") OR (TransactionStatus="PUBLISHED") 
| append [search index=myindex2 (logMessage="Producer created new event") event="delivered" OR event="processed" serviceName="abc" [search index=myindex uuid=98as786-ffe6-4de1-929y-080e99bc2e6r AND status="SUCCESS" AND serviceName="abc" | top limit=1 headerId | fields + headerId | rename headerId as message_id]]
| streamstats count as event_num by uuid
| eventstats max(event_num) as total_events by uuid
| eventstats values(eval(if(event_num=3, event, null()))) as third_event by uuid
| eval transaction_status=case(
    total_events=3 AND third_event="delivered", "COMPLETE",
    total_events>=3 AND third_event!="delivered", "PENDING",
    total_events<3, "ERROR"
)
| dedup uuid transaction_status
| stats count as "UUID Count" by transaction_status

Quick Dashboard Setup Tips

Once the query works:

  • Add it to a Table panel to show all status counts side-by-side
  • Use Single Value panels for individual statuses (filter by transaction_status="COMPLETE" etc.) for at-a-glance metrics
  • Adjust the time range picker to match your typical transaction lifecycle

内容的提问来源于stack exchange,提问作者Kumar Dev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 08:56:06