<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding (hostname) field to Uptime Monitoring / Status Overview Dash in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Adding-hostname-field-to-Uptime-Monitoring-Status-Overview-Dash/m-p/478389#M82131</link>
    <description>&lt;P&gt;Thanks for your response and I apologize for lack of clarity.&lt;/P&gt;

&lt;P&gt;I am working in the 'Network Toolkit' App under the 'Status Overview' portion to provide ICMP monitoring for various hosts.&lt;BR /&gt;
Currently the 'Status Overview' provides a 'dest' field that contains an IP address, and I would like to create an additional 'hostname' field respectively for easier reference with the IP of a particular host.&lt;/P&gt;

&lt;P&gt;Splunk support has provided me with a suggestion in creating a lookup which contains an IP address and Hostname imported via CSV file for each host.  I've managed to create a lookup, but trying to use the 'inputlookup' command is failing for me probably because I am a noob and not using it correctly.&lt;/P&gt;

&lt;P&gt;An additional option is under 'Settings' / 'Data Inputs' / 'Ping' . Within this dash there is a 'name' field which is populated entering a new host from this dash.  If I could somehow grab that field from here and merge with the data in the 'Status Overview' dash , that could work too. &lt;/P&gt;

&lt;P&gt;Any assist would be greatly appreciated on this. Btw I tried importing screen snips but don't see where to import within this.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Thanks &lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Tue, 05 Nov 2019 17:21:30 GMT</pubDate>
    <dc:creator>archersplunk</dc:creator>
    <dc:date>2019-11-05T17:21:30Z</dc:date>
    <item>
      <title>Adding (hostname) field to Uptime Monitoring / Status Overview Dash</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-hostname-field-to-Uptime-Monitoring-Status-Overview-Dash/m-p/478387#M82129</link>
      <description>&lt;P&gt;What would be the best way to add 'hostname' field to the 'Status Overview' dash under Uptime Monitoring. I noticed under 'Data Inputs' / 'Ping' , a name(hostname) exists as new hosts are added.  Would there be a way to join this field over into my data for 'Uptime Monitoring'? Been at this a while and seems like the answer is much more simple then I'm looking at this. Thanks. &lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2019 22:41:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-hostname-field-to-Uptime-Monitoring-Status-Overview-Dash/m-p/478387#M82129</guid>
      <dc:creator>archersplunk</dc:creator>
      <dc:date>2019-11-04T22:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: Adding (hostname) field to Uptime Monitoring / Status Overview Dash</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-hostname-field-to-Uptime-Monitoring-Status-Overview-Dash/m-p/478388#M82130</link>
      <description>&lt;P&gt;We're going to need more information to work with. For starters, what app are you working in? What have you tried? What isn't working? Screenshots are often helpful, too.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 00:27:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-hostname-field-to-Uptime-Monitoring-Status-Overview-Dash/m-p/478388#M82130</guid>
      <dc:creator>nplamondon</dc:creator>
      <dc:date>2019-11-05T00:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Adding (hostname) field to Uptime Monitoring / Status Overview Dash</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-hostname-field-to-Uptime-Monitoring-Status-Overview-Dash/m-p/478389#M82131</link>
      <description>&lt;P&gt;Thanks for your response and I apologize for lack of clarity.&lt;/P&gt;

&lt;P&gt;I am working in the 'Network Toolkit' App under the 'Status Overview' portion to provide ICMP monitoring for various hosts.&lt;BR /&gt;
Currently the 'Status Overview' provides a 'dest' field that contains an IP address, and I would like to create an additional 'hostname' field respectively for easier reference with the IP of a particular host.&lt;/P&gt;

&lt;P&gt;Splunk support has provided me with a suggestion in creating a lookup which contains an IP address and Hostname imported via CSV file for each host.  I've managed to create a lookup, but trying to use the 'inputlookup' command is failing for me probably because I am a noob and not using it correctly.&lt;/P&gt;

&lt;P&gt;An additional option is under 'Settings' / 'Data Inputs' / 'Ping' . Within this dash there is a 'name' field which is populated entering a new host from this dash.  If I could somehow grab that field from here and merge with the data in the 'Status Overview' dash , that could work too. &lt;/P&gt;

&lt;P&gt;Any assist would be greatly appreciated on this. Btw I tried importing screen snips but don't see where to import within this.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Thanks &lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 05 Nov 2019 17:21:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-hostname-field-to-Uptime-Monitoring-Status-Overview-Dash/m-p/478389#M82131</guid>
      <dc:creator>archersplunk</dc:creator>
      <dc:date>2019-11-05T17:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: Adding (hostname) field to Uptime Monitoring / Status Overview Dash</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-hostname-field-to-Uptime-Monitoring-Status-Overview-Dash/m-p/478390#M82132</link>
      <description>&lt;P&gt;Assuming the columns for your lookup table are titled "dest" and "hostname" and your lookup is  named "hostnameLookup.csv" you would add the following to your search: " | lookup hostnameLookup.csv dest OUTPUT hostname&lt;/P&gt;

&lt;P&gt;Complete search:&lt;BR /&gt;
sourcetype="ping_input"&lt;BR /&gt;
| stats sparkline(avg(avg_ping)) as sparkline_ping avg(avg_ping) as ping max(max_ping) as max_ping latest(packet_loss) as packet_loss latest(_time) as last_checked range(avg_ping) as range min(avg_ping) as min by dest&lt;BR /&gt;
| search &lt;BR /&gt;
| eval ping=round(ping, 0)." ms"&lt;BR /&gt;
| eval average=round(avg_ping, 0)." ms"&lt;BR /&gt;
| eval maximum=round(max_ping, 0)." ms"&lt;BR /&gt;
| eval range=round(min, 0)." - ".round(min+range, 0)." ms"&lt;BR /&gt;
| eval packet_loss=if(max_ping="NA",100,packet_loss)&lt;BR /&gt;
| lookup hostnameLookup.csv dest OUTPUT hostname&lt;BR /&gt;
| table dest hostname packet_loss last_checked ping max_ping range sparkline_ping &lt;BR /&gt;
| &lt;CODE&gt;timesince(last_checked,last_checked)&lt;/CODE&gt;&lt;BR /&gt;
| sort -ping&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:52:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-hostname-field-to-Uptime-Monitoring-Status-Overview-Dash/m-p/478390#M82132</guid>
      <dc:creator>mledford</dc:creator>
      <dc:date>2020-09-30T02:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Adding (hostname) field to Uptime Monitoring / Status Overview Dash</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-hostname-field-to-Uptime-Monitoring-Status-Overview-Dash/m-p/478391#M82133</link>
      <description>&lt;P&gt;Thank you so much for this answer as it was 99% of the key to my resolution. The other 1% was adding in an 'as' to reference the IP field from the lookup to my data, then OUTPUT that to the newly created field&lt;/P&gt;

&lt;P&gt;|lookup hostnameLookup.csv IP as dest OUTPUT hostname&lt;/P&gt;

&lt;P&gt;Worked perfect and could not have done it without your awesomeness.&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2019 19:57:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-hostname-field-to-Uptime-Monitoring-Status-Overview-Dash/m-p/478391#M82133</guid>
      <dc:creator>archersplunk</dc:creator>
      <dc:date>2019-11-05T19:57:42Z</dc:date>
    </item>
  </channel>
</rss>

