# Splunk to Elastic query migration

**URL:** <https://discuss.elastic.co/t/splunk-to-elastic-query-migration/188708>\
**Category:** Elasticsearch\
**Created:** [July 3, 2019, 12:48pm UTC](https://discuss.elastic.co/t/splunk-to-elastic-query-migration/188708 "2019-07-03T12:48:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ravitandur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ravitandur/32/4568_2.png) [@ravitandur](https://discuss.elastic.co/u/ravitandur)\
**Post date:** [July 3, 2019, 12:48pm UTC](https://discuss.elastic.co/t/splunk-to-elastic-query-migration/188708/1 "2019-07-03T12:48:50Z")

</div>

We have below Splunk query:

sourcetype=f5\_access\_log rescode=429 | transaction node,rescode maxevents=-1 maxpause=1s | search eventcount\>1 duration \> 1 | bin span=5 duration | top 100 duration

Can some one please help me in understanding transaction part of the query and how to implement the similar query in Elastic.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 5, 2019, 8:08am UTC](https://discuss.elastic.co/t/splunk-to-elastic-query-migration/188708/2 "2019-07-05T08:08:51Z")

</div>

> [@ravitandur](#):
>
> Can some one please help me in understanding transaction part of the query and how to implement the similar query in Elastic.

What do the Splunk docs say about the transaction part? I don't know that a heap of people that know it would be hanging out here.

---

<div class="post-metadata">

**Author:** ![ravitandur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ravitandur/32/4568_2.png) [@ravitandur](https://discuss.elastic.co/u/ravitandur)\
**Post date:** [July 8, 2019, 6:57am UTC](https://discuss.elastic.co/t/splunk-to-elastic-query-migration/188708/3 "2019-07-08T06:57:26Z")

</div>

😀 ok let me check my self. I will update this thread after my analysis.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2019, 7:10am UTC](https://discuss.elastic.co/t/splunk-to-elastic-query-migration/188708/4 "2019-08-05T07:10:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
