<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to create the below alert? in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381415#M11376</link>
    <description>&lt;P&gt;Just to understand your question better and for example &lt;BR /&gt;
/logs/web/output/accm/060418_1002_CAP_sat1svmap504_cert_details.log&lt;BR /&gt;
from this source ONLY  this part (060418_1002_) is dynamic and changes , should events from this source be logged for the day, right?&lt;BR /&gt;
Hint - If my understanding is true  /logs/web/output/accm/CAP_sat1svmap504_cert_details.log  - with &lt;BR /&gt;
(060418_1002_CAP) removed, the remaining part for this source always remains constant?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 19:53:47 GMT</pubDate>
    <dc:creator>Sukisen1981</dc:creator>
    <dc:date>2020-09-29T19:53:47Z</dc:date>
    <item>
      <title>How to create the below alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381412#M11373</link>
      <description>&lt;P&gt;I have below source. now I have to create an alert if any source is missing everyday. The file name changes everyday as it starts with a timestamp i.e. in this case we have  "060418_1002" which will change everyday. Help me on the same.&lt;BR /&gt;
Cant use lookup to compare as file name changes because it starts with a timestamp.&lt;/P&gt;

&lt;P&gt;Below are the sample sources.&lt;/P&gt;

&lt;P&gt;/logs/web/output/accm/060418_1002_CAP_sat1svmap504_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/060418_1003_CAP_sat1svmap504_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/060818_0300_CAP_dfw1svpap505_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/060818_0300_CAP_sat1svmap536_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/060818_0300_PROD_dfw1svpap505_cert_details.log&lt;BR /&gt;
/logs/web/output/sc/060418_1105_PROD_dfw1svpap621_cert_details.log&lt;BR /&gt;
/logs/web/output/sc/060418_1106_PSP1_dfw1svpap621_cert_details.log&lt;BR /&gt;
/logs/web/output/sc/060818_0230_UAT1_sat1svmap628_cert_details.log&lt;BR /&gt;
/logs/web/output/sc/060818_0230_UAT1_sat1svmap629_cert_details.log&lt;BR /&gt;
/logs/web/output/smartauction2.0/052518_1530_CAP1_sat1svmap660_cert_details.log&lt;BR /&gt;
/logs/web/output/smartauction2.0/052518_1530_PRD1_sat1svmap660_cert_details.log&lt;BR /&gt;
/logs/web/output/smartauction2.0/052518_1530_PSP1_dfw1svpap661_cert_details.log&lt;BR /&gt;
/logs/web/output/smartauction2.0/052518_1530_PSP1_sat1svmap660_cert_details.log&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:58:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381412#M11373</guid>
      <dc:creator>abhi04</dc:creator>
      <dc:date>2020-09-29T19:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to create the below alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381413#M11374</link>
      <description>&lt;P&gt;Hi @abhi04&lt;/P&gt;

&lt;P&gt;why dont you create an alert in a usual way&lt;/P&gt;

&lt;P&gt;your search | stats dc(source) as sourcecount &lt;/P&gt;

&lt;P&gt;&amp;amp; in trigger conditions ---- choose Custom --- sourcecount&amp;lt;13&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 16:20:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381413#M11374</guid>
      <dc:creator>PowerPacked</dc:creator>
      <dc:date>2018-06-12T16:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to create the below alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381414#M11375</link>
      <description>&lt;P&gt;I want to list the source as well which all are missing.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 16:23:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381414#M11375</guid>
      <dc:creator>abhi04</dc:creator>
      <dc:date>2018-06-12T16:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to create the below alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381415#M11376</link>
      <description>&lt;P&gt;Just to understand your question better and for example &lt;BR /&gt;
/logs/web/output/accm/060418_1002_CAP_sat1svmap504_cert_details.log&lt;BR /&gt;
from this source ONLY  this part (060418_1002_) is dynamic and changes , should events from this source be logged for the day, right?&lt;BR /&gt;
Hint - If my understanding is true  /logs/web/output/accm/CAP_sat1svmap504_cert_details.log  - with &lt;BR /&gt;
(060418_1002_CAP) removed, the remaining part for this source always remains constant?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:53:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381415#M11376</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2020-09-29T19:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to create the below alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381416#M11377</link>
      <description>&lt;P&gt;Yes, correct.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2018 16:45:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381416#M11377</guid>
      <dc:creator>abhi04</dc:creator>
      <dc:date>2018-06-12T16:45:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to create the below alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381417#M11378</link>
      <description>&lt;P&gt;After seeing the below answer and your comment I am more confused now,&lt;BR /&gt;
to me the first 2 rows are from the same source but the third row is a different source, is that correct? If so this is what you need to do - &lt;BR /&gt;
1- Use the substr function to eliminate the dynamic parts from all the source entries, let us call this field src.&lt;BR /&gt;
2- |eventstats max(_time) as last_time by src.&lt;BR /&gt;
3- extract the date time part from now() and the same from last_time. now() gives you today's datetime. if the extracted date times are not equal to each other, your respective src did not have any entries today.&lt;BR /&gt;
4-I suspect though, you actualy may want to check not for today but for yesterday (assuming the source can log anytime on any given day till 11:59 PM), in that case you just need to subtract 1 day each from now() and last_time before extracting the date times to make a comparision&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:53:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381417#M11378</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2020-09-29T19:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to create the below alert?</title>
      <link>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381418#M11379</link>
      <description>&lt;P&gt;Hi sukisen,&lt;/P&gt;

&lt;P&gt;For more clarification, Below is the sources for one host for last two days.&lt;/P&gt;

&lt;P&gt;For 12 June:&lt;/P&gt;

&lt;P&gt;/logs/web/output/accm/061218_0300_CAP_dfw1svpap505_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_CAP_sat1svmap535_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_CAP_sat1svmap536_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_PROD_dfw1svpap505_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_PROD_dfw1svpap506_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_PROD_dfw1svpap507_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_PROD_sat1svmap535_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_PROD_sat1svmap536_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_PROD_sat1svmap537_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_PROD_sat1svmap538_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_UAT_dfw1svpap505_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_UAT_dfw1svpap506_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_UAT_dfw1svpap507_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_UAT_sat1svmap535_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_UAT_sat1svmap536_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_UAT_sat1svmap537_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_0300_UAT_sat1svmap538_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_1500_CAP_sat1svmap504_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_1500_CAP_sat1svmap505_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_1500_CAP_sat1svmap506_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061218_1500_CAP_sat1svmap507_cert_details.log&lt;/P&gt;

&lt;P&gt;For 13 June:&lt;BR /&gt;
/logs/web/output/accm/061318_0300_CAP_dfw1svpap504_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_CAP_dfw1svpap505_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_CAP_sat1svmap535_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_CAP_sat1svmap536_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_PROD_dfw1svpap504_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_PROD_dfw1svpap505_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_PROD_dfw1svpap506_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_PROD_dfw1svpap507_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_PROD_sat1svmap535_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_PROD_sat1svmap536_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_PROD_sat1svmap537_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_PROD_sat1svmap538_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_UAT_dfw1svpap504_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_UAT_dfw1svpap505_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_UAT_dfw1svpap506_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_UAT_dfw1svpap507_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_UAT_sat1svmap535_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_UAT_sat1svmap536_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_UAT_sat1svmap537_cert_details.log&lt;BR /&gt;
/logs/web/output/accm/061318_0300_UAT_sat1svmap538_cert_details.log&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:59:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/How-to-create-the-below-alert/m-p/381418#M11379</guid>
      <dc:creator>abhi04</dc:creator>
      <dc:date>2020-09-29T19:59:22Z</dc:date>
    </item>
  </channel>
</rss>

