<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to create a live up or down Dahboard view in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-live-up-or-down-dashboard-view/m-p/507600#M86385</link>
    <description>&lt;P&gt;I'm not familiar with your specific dataset, however you would want to come up with a base query that matches the events in Splunk that have the states you are trying to track.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i.e.&lt;/P&gt;&lt;P&gt;index=myindex sourcetype=mysourcetype host IN (host1,host2,host3) service IN (service1,service2,service3)&lt;/P&gt;&lt;P&gt;note: you can wildcard parts of the host or service filters with * as well. If wanting all hosts and services, you probably don't need to add a host or service constraint.&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jul 2020 15:18:36 GMT</pubDate>
    <dc:creator>bandit</dc:creator>
    <dc:date>2020-07-06T15:18:36Z</dc:date>
    <item>
      <title>How to create a live up or down dashboard view?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-live-up-or-down-dashboard-view/m-p/507586#M86382</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_0-1594045928296.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9493iCF44B0A1866DF119/image-size/large?v=v2&amp;amp;px=999" role="button" title="sphiwee_0-1594045928296.png" alt="sphiwee_0-1594045928296.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Good day is it possible to get above visualization on Splunk? im kinda new and lost, I designed this myself using PowerPoint. We want to get a view of all the services running in our servers to be like the above image on Splunk dashboards.&amp;nbsp; We are currently running a cron script on our server and forwarding the results to our Splunk server every 5 minutes.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_1-1594046342208.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9494iC42A3C0B1AF872F4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sphiwee_1-1594046342208.png" alt="sphiwee_1-1594046342208.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The results look like the above screenshot. We want a live view of all the services running with green being up and red being down.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 16:56:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-live-up-or-down-dashboard-view/m-p/507586#M86382</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-07-07T16:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: how to create a live up or down Dahboard view</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-live-up-or-down-dashboard-view/m-p/507594#M86383</link>
      <description>&lt;P&gt;your base query | dedup host application | chart values(state) over host by application&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;note: modify fields names to match your dataset&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then you can color code in a table or single value chart using trellis option&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="color-code-table-values.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9497i14DEA048D47D18BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="color-code-table-values.jpg" alt="color-code-table-values.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 15:33:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-live-up-or-down-dashboard-view/m-p/507594#M86383</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2020-07-06T15:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: how to create a live up or down Dahboard view</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-live-up-or-down-dashboard-view/m-p/507598#M86384</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/221005"&gt;@bandit&lt;/a&gt;&amp;nbsp;thank you sir, what do I add to my base query? all the services? separated by OR ?&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 15:02:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-live-up-or-down-dashboard-view/m-p/507598#M86384</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-07-06T15:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: how to create a live up or down Dahboard view</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-live-up-or-down-dashboard-view/m-p/507600#M86385</link>
      <description>&lt;P&gt;I'm not familiar with your specific dataset, however you would want to come up with a base query that matches the events in Splunk that have the states you are trying to track.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i.e.&lt;/P&gt;&lt;P&gt;index=myindex sourcetype=mysourcetype host IN (host1,host2,host3) service IN (service1,service2,service3)&lt;/P&gt;&lt;P&gt;note: you can wildcard parts of the host or service filters with * as well. If wanting all hosts and services, you probably don't need to add a host or service constraint.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 15:18:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-live-up-or-down-dashboard-view/m-p/507600#M86385</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2020-07-06T15:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: how to create a live up or down Dahboard view</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-live-up-or-down-dashboard-view/m-p/507624#M86387</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/221005"&gt;@bandit&lt;/a&gt;&amp;nbsp;typing your solution&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_1-1594052932087.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9500i47372E627F3510E0/image-size/large?v=v2&amp;amp;px=999" role="button" title="sphiwee_1-1594052932087.png" alt="sphiwee_1-1594052932087.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;heres what my data looks like, circled in black is what i could use to get the up status, sorry for this but the documentation is also not helping&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sphiwee_2-1594053267181.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9501iDA0794460FBFC43C/image-size/large?v=v2&amp;amp;px=999" role="button" title="sphiwee_2-1594053267181.png" alt="sphiwee_2-1594053267181.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 16:36:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-live-up-or-down-dashboard-view/m-p/507624#M86387</guid>
      <dc:creator>sphiwee</dc:creator>
      <dc:date>2020-07-06T16:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: how to create a live up or down Dahboard view</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-live-up-or-down-dashboard-view/m-p/507636#M86393</link>
      <description>&lt;P&gt;Ok, I would first start with verifying that either the "RUNNING"/"NOT RUNNING"&amp;nbsp; values&amp;nbsp;(I'm assuming there is an inverse value to RUNNING) are recognized by Splunk as a field. You can check apps.splunk.com to see if there is an addon that will parse your sourcetype into key/value pairs or you may have to write regex to capture the value of the run state into a field. Once it's in a field you can run statistic commands against that field such as | top state by host&lt;/P&gt;&lt;P&gt;example inline regex command to extract the state&lt;/P&gt;&lt;P&gt;| rex "(?&amp;lt;state&amp;gt;(RUNNING|DOWN))"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="extract-fields.jpg" style="width: 494px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9502iA3A93595C0F925FE/image-size/large?v=v2&amp;amp;px=999" role="button" title="extract-fields.jpg" alt="extract-fields.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If you are getting overwhelmed, you may want to start with one of the free classes which will cover fields in Splunk&amp;nbsp;&lt;A href="https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html" target="_blank" rel="noopener"&gt;https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I also noticed you are running a script from crontab. You could modify the format of your log to log in key-pair values. i.e. process_status="RUNNING" or process_status="UP" or process_status="DOWN" etc.&lt;/P&gt;&lt;P&gt;When Splunk encounters key/pair values it will auto extract fields which should make this task much simpler.&lt;/P&gt;&lt;P&gt;&lt;A href="https://dev.splunk.com/enterprise/docs/developapps/logging/loggingbestpractices/" target="_blank" rel="noopener"&gt;https://dev.splunk.com/enterprise/docs/developapps/logging/loggingbestpractices/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 15:26:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-create-a-live-up-or-down-dashboard-view/m-p/507636#M86393</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2020-07-07T15:26:40Z</dc:date>
    </item>
  </channel>
</rss>

