<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: create alert in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/create-alert/m-p/568905#M8616</link>
    <description>&lt;LI-CODE lang="markup"&gt;| rex "Caused by: (?&amp;lt;cause&amp;gt;([^:]+:){3}).*queue manager '(?&amp;lt;queuemanager&amp;gt;[^']+).*host name '(?&amp;lt;hostname&amp;gt;[^']+)"&lt;/LI-CODE&gt;</description>
    <pubDate>Wed, 29 Sep 2021 10:03:41 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2021-09-29T10:03:41Z</dc:date>
    <item>
      <title>create alert</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/create-alert/m-p/568904#M8615</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; I have logs in splunk and i need to create field values and create table with the values,present in logs.&lt;/P&gt;&lt;P&gt;example :&lt;SPAN class="t"&gt;Caused&lt;/SPAN&gt; &lt;SPAN class="t"&gt;by:&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class="t"&gt;org.apache.kafka.connect.errors.ConnectException:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Failed&lt;/SPAN&gt; &lt;SPAN class="t"&gt;to&lt;/SPAN&gt; &lt;SPAN class="t"&gt;start&lt;/SPAN&gt; &lt;SPAN class="t"&gt;new&lt;/SPAN&gt; &lt;SPAN class="t"&gt;JMS&lt;/SPAN&gt; &lt;SPAN class="t"&gt;session&lt;/SPAN&gt; &lt;SPAN class="t"&gt;connection&lt;/SPAN&gt; &lt;SPAN class="t"&gt;1:&lt;/SPAN&gt; &lt;/STRONG&gt;&lt;SPAN class="t"&gt;&lt;STRONG&gt;JMSWMQ2013&lt;/STRONG&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;The&lt;/SPAN&gt; &lt;SPAN class="t"&gt;security&lt;/SPAN&gt; &lt;SPAN class="t"&gt;authentication&lt;/SPAN&gt; &lt;SPAN class="t"&gt;was&lt;/SPAN&gt; &lt;SPAN class="t"&gt;not&lt;/SPAN&gt; &lt;SPAN class="t"&gt;valid&lt;/SPAN&gt; &lt;SPAN class="t"&gt;that&lt;/SPAN&gt; &lt;SPAN class="t"&gt;was&lt;/SPAN&gt; &lt;SPAN class="t"&gt;supplied&lt;/SPAN&gt; &lt;SPAN class="t"&gt;for&lt;/SPAN&gt; &lt;STRONG&gt;&lt;SPAN class="t"&gt;queue&lt;/SPAN&gt; &lt;SPAN class="t"&gt;manager&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;EVT302&lt;/SPAN&gt;' &lt;/STRONG&gt;&lt;SPAN class="t"&gt;with&lt;/SPAN&gt; &lt;SPAN class="t"&gt;connection&lt;/SPAN&gt; &lt;SPAN class="t"&gt;mode&lt;/SPAN&gt;&lt;SPAN&gt; '&lt;/SPAN&gt;&lt;SPAN class="t"&gt;Client&lt;/SPAN&gt;&lt;SPAN&gt;' &lt;/SPAN&gt;&lt;SPAN class="t"&gt;and&lt;/SPAN&gt; &lt;SPAN class="t"&gt;host&lt;/SPAN&gt; &lt;SPAN class="t"&gt;name&lt;/SPAN&gt;&lt;SPAN&gt; '&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class="t"&gt;10.37.84.12&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;10.37.100.13&lt;/SPAN&gt;(&lt;SPAN class="t"&gt;1442&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&lt;STRONG&gt;)&lt;/STRONG&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Above one is the example log and i need to extract value under caused by as description and queue manager number and also the hostname.&amp;nbsp;&lt;BR /&gt;Can anyone help me on the same.&lt;/P&gt;&lt;P&gt;Thanks in Advance.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 09:53:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/create-alert/m-p/568904#M8615</guid>
      <dc:creator>vineela</dc:creator>
      <dc:date>2021-09-29T09:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: create alert</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/create-alert/m-p/568905#M8616</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex "Caused by: (?&amp;lt;cause&amp;gt;([^:]+:){3}).*queue manager '(?&amp;lt;queuemanager&amp;gt;[^']+).*host name '(?&amp;lt;hostname&amp;gt;[^']+)"&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 29 Sep 2021 10:03:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/create-alert/m-p/568905#M8616</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-09-29T10:03:41Z</dc:date>
    </item>
  </channel>
</rss>

