<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need seperate count for UP and DOWN Peer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Need-seperate-count-for-UP-and-DOWN-Peer/m-p/481725#M82571</link>
    <description>&lt;P&gt;thanks for the query it helped. &lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2020 10:36:08 GMT</pubDate>
    <dc:creator>jerinvarghese</dc:creator>
    <dc:date>2020-01-10T10:36:08Z</dc:date>
    <item>
      <title>Need seperate count for UP and DOWN Peer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-seperate-count-for-UP-and-DOWN-Peer/m-p/481720#M82566</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I have a query to display some BGP neighbour UP or DOWN.&lt;/P&gt;

&lt;P&gt;Output looks like &lt;BR /&gt;
nodelabel   Status  PEER_IP  Time_CST&lt;BR /&gt;
Device1 UP  10.253.226.10   01/08/20 02:03:53&lt;BR /&gt;
Device2 DOWN    10.253.140.89   01/08/20 00:26:54&lt;/P&gt;

&lt;P&gt;Query is : &lt;/P&gt;

&lt;P&gt;index=opennms eventuei="uei.opennms.org/thresholds/bgpPeerState/XOM*" "WANRT*" "10.253*"&lt;BR /&gt;
| rex field=eventuei "uei.opennms.org/thresholds/bgpPeerState/(?.+)"&lt;BR /&gt;
|  rex "peer: (?.*), eventseverity" &lt;BR /&gt;
| eval Status=case(bgpPeerState=="XOM-rearm", "UP", bgpPeerState=="XOM-falling", "DOWN", 1=1, "Other")&lt;BR /&gt;
 | rename _time as Time_CST&lt;BR /&gt;
  | fieldformat Time_CST=strftime(Time_CST,"%x %X")&lt;BR /&gt;
| dedup nodelabel sortby - Time_CST &lt;BR /&gt;
| table nodelabel Status PEER_IP Time_CST&lt;/P&gt;

&lt;P&gt;I need a help, want to display how many UP and DOWN peers there.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:37:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-seperate-count-for-UP-and-DOWN-Peer/m-p/481720#M82566</guid>
      <dc:creator>jerinvarghese</dc:creator>
      <dc:date>2020-09-30T03:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Need seperate count for UP and DOWN Peer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-seperate-count-for-UP-and-DOWN-Peer/m-p/481721#M82567</link>
      <description>&lt;P&gt;use something like this on the end?&lt;/P&gt;

&lt;P&gt;| stats count as Total count(eval(Status=="UP")) as "up_count" count(eval(Status=="DOWN")) as "down_count"&lt;/P&gt;

&lt;P&gt;Or &lt;/P&gt;

&lt;P&gt;index=opennms eventuei="uei.opennms.org/thresholds/bgpPeerState/XOM*" "WANRT*" "10.253*"&lt;BR /&gt;
| rex field=eventuei "uei.opennms.org/thresholds/bgpPeerState/(?.+)"&lt;BR /&gt;
| rex "peer: (?.*), eventseverity"&lt;BR /&gt;
| eval Status=case(bgpPeerState=="XOM-rearm", "UP", bgpPeerState=="XOM-falling", "DOWN", 1=1, "Other")&lt;BR /&gt;
| dedup nodelabel&lt;BR /&gt;
| stats dc(PEER_IP) as Total by Status&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:34:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-seperate-count-for-UP-and-DOWN-Peer/m-p/481721#M82567</guid>
      <dc:creator>WalshyB</dc:creator>
      <dc:date>2020-09-30T03:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Need seperate count for UP and DOWN Peer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-seperate-count-for-UP-and-DOWN-Peer/m-p/481722#M82568</link>
      <description>&lt;P&gt;@jerinvarghese &lt;BR /&gt;
Try&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;YOUR_SEARCH | stats count(eval(Status="UP")) as UP_Count count(eval(Status="DOWN")) as DOWN_Count
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 10 Jan 2020 10:07:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-seperate-count-for-UP-and-DOWN-Peer/m-p/481722#M82568</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2020-01-10T10:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: Need seperate count for UP and DOWN Peer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-seperate-count-for-UP-and-DOWN-Peer/m-p/481723#M82569</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;First method:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=opennms eventuei="uei.opennms.org/thresholds/bgpPeerState/XOM*" "WANRT*" "10.253*"
| rex field=eventuei "uei.opennms.org/thresholds/bgpPeerState/(?.+)"
| rex "peer: (?.*), eventseverity"
| eval Status=case(bgpPeerState=="XOM-rearm", "UP", bgpPeerState=="XOM-falling", "DOWN", 1=1, "Other")
| rename _time as Time_CST
| fieldformat Time_CST=strftime(Time_CST,"%x %X")
| dedup nodelabel sortby - Time_CST
| table nodelabel Status PEER_IP Time_CST
| eval number_Up=if(Status="UP",1,0), number_Down=if(Status="DOWN",1,0)
| stats sum(number_Up) as UP, sum(number_Down) as DOWN
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Second method:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=opennms eventuei="uei.opennms.org/thresholds/bgpPeerState/XOM*" "WANRT*" "10.253*"
    | rex field=eventuei "uei.opennms.org/thresholds/bgpPeerState/(?.+)"
    | rex "peer: (?.*), eventseverity"
    | eval Status=case(bgpPeerState=="XOM-rearm", "UP", bgpPeerState=="XOM-falling", "DOWN", 1=1, "Other")
    | rename _time as Time_CST
    | fieldformat Time_CST=strftime(Time_CST,"%x %X")
    | dedup nodelabel sortby - Time_CST
    | table nodelabel Status PEER_IP Time_CST
    | stats count(eval(Status="UP")) as UP, count(eval(Status="DOWN")) as DOWN
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 10 Jan 2020 10:26:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-seperate-count-for-UP-and-DOWN-Peer/m-p/481723#M82569</guid>
      <dc:creator>TISKAR</dc:creator>
      <dc:date>2020-01-10T10:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Need seperate count for UP and DOWN Peer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-seperate-count-for-UP-and-DOWN-Peer/m-p/481724#M82570</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;index=opennms eventuei="uei.opennms.org/thresholds/bgpPeerState/XOM*" "WANRT*" "10.253.*"
| rex "peer: (?&amp;lt;PEER_IP&amp;gt;.*), eventseverity"
| stats count(eval(searchmatch("XOM-rearm"))) AS UP count(eval(searchmatch("XOM-falling"))) AS DOWN values(PEER_IP) AS PEER_IP by nodelabel
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;hi, only count up &amp;amp; down by nodelabel.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 10:34:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-seperate-count-for-UP-and-DOWN-Peer/m-p/481724#M82570</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-01-10T10:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: Need seperate count for UP and DOWN Peer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-seperate-count-for-UP-and-DOWN-Peer/m-p/481725#M82571</link>
      <description>&lt;P&gt;thanks for the query it helped. &lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2020 10:36:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-seperate-count-for-UP-and-DOWN-Peer/m-p/481725#M82571</guid>
      <dc:creator>jerinvarghese</dc:creator>
      <dc:date>2020-01-10T10:36:08Z</dc:date>
    </item>
  </channel>
</rss>

