<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URL Monitoring issue in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582224#M13413</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239496"&gt;@jackin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This means that there's a parsing error, if you could share a sample of your logs, I could help you to create another field extraction.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jan 2022 09:59:35 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-01-24T09:59:35Z</dc:date>
    <item>
      <title>URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582212#M13407</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We have a few URLs being monitored by a Splunk&amp;nbsp;alert(query pasted below for reference) by making use of the "Website Monitoring" add on.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index=myindex sourcetype="web_ping"&lt;BR /&gt;[| inputlookup URL.csv]&lt;BR /&gt;| streamstats count by response_code url&lt;BR /&gt;| where count&amp;gt;=2 and response_code&amp;gt;=300&lt;BR /&gt;| eval Timestamp=strftime(_time ,"%d/%m/%Y %H:%M:%S"),Status="Failure"&lt;BR /&gt;| rename response_code as "HTTP Response Code" url as URL&lt;BR /&gt;| dedup URL&lt;BR /&gt;| table Timestamp "HTTP Response Code" URL Status&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Here the problem is&amp;nbsp;&lt;BR /&gt;we are receiving &lt;SPAN&gt;response_code and&amp;nbsp;response_time fields as empty like below&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;proxy_server=&lt;/SPAN&gt;"" &lt;SPAN class=""&gt;title=abc.com&lt;/SPAN&gt; &lt;SPAN class=""&gt;timed_out=False&lt;/SPAN&gt; &lt;SPAN class=""&gt;proxy_port=&lt;/SPAN&gt;"" &lt;SPAN class=""&gt;url=&lt;A href="https://abc.com" target="_blank" rel="noopener"&gt;https://abc.com&lt;/A&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;total_time=&lt;/SPAN&gt;"" &lt;SPAN class=""&gt;request_time=&lt;/SPAN&gt;"" &lt;SPAN class=""&gt;timeout=120&lt;/SPAN&gt; &lt;SPAN class=""&gt;response_code=&lt;/SPAN&gt;"" &lt;SPAN class=""&gt;proxy_type=http&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;can anyone suggest to resolve (troubleshooting steps) this issue.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 08:26:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582212#M13407</guid>
      <dc:creator>jackin</dc:creator>
      <dc:date>2022-01-24T08:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582213#M13408</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239496"&gt;@jackin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;what is the problem: aren't the missed fields extracted from logs or what else?&lt;/P&gt;&lt;P&gt;could you share some samples of your logs, bolding the missed fields?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 08:30:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582213#M13408</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-24T08:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582216#M13409</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jackin_0-1643013685736.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17658iBBA3A0CAE0C4CEBA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jackin_0-1643013685736.png" alt="jackin_0-1643013685736.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Like above snap some fileds are empty&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 08:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582216#M13409</guid>
      <dc:creator>jackin</dc:creator>
      <dc:date>2022-01-24T08:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582217#M13410</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239496"&gt;@jackin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the question is: are they empty because they aren't present or because there's a parsing error?&lt;/P&gt;&lt;P&gt;for this reason I asked a sample of your log, with the missing values.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 08:46:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582217#M13410</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-24T08:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582220#M13411</link>
      <description>&lt;P&gt;Thats an issue with that add-on. I think you need to highlight that to developer. Or you need to readjust the frequency it polls or reduce no of urls on the hf where addon is .&lt;/P&gt;&lt;P&gt;But I used to eval that empty code as 404 or url unreachable&amp;nbsp; and then you will have value instead of empty value.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 09:10:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582220#M13411</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-24T09:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582222#M13412</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For ex: we are trying to access one of the url htttps://.... , so basically it is giving as HTTP Error 503 , But Splunk is showing HTTPP response code as null .&lt;/P&gt;&lt;P&gt;So, we can say that it's a parsing error&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 09:30:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582222#M13412</guid>
      <dc:creator>jackin</dc:creator>
      <dc:date>2022-01-24T09:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582224#M13413</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239496"&gt;@jackin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This means that there's a parsing error, if you could share a sample of your logs, I could help you to create another field extraction.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 09:59:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582224#M13413</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-24T09:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582226#M13414</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for help&lt;/P&gt;&lt;P&gt;where it is available ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 10:15:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582226#M13414</guid>
      <dc:creator>jackin</dc:creator>
      <dc:date>2022-01-24T10:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582229#M13415</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239496" target="_blank"&gt;@jackin&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;As I said, probably there's a parsing error in your TA, so the easiest way is to create a new field extraction.&lt;/P&gt;&lt;P&gt;But to do this, I need that you share a sample of your logs.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 10:24:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582229#M13415</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-24T10:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582231#M13416</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am asking which logs you need and where it is available&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 10:46:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582231#M13416</guid>
      <dc:creator>jackin</dc:creator>
      <dc:date>2022-01-24T10:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582232#M13417</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239496"&gt;@jackin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you could send the logs that you have in the print screen you shared.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 10:52:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582232#M13417</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-24T10:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582235#M13418</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PFB log&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;proxy_server=&lt;/SPAN&gt;&lt;SPAN&gt;"" &lt;/SPAN&gt;&lt;SPAN class=""&gt;title=internal-onyxquals-738401111.eu-west-1.elb.amazonaws.com&lt;/SPAN&gt; &lt;SPAN class=""&gt;timed_out=True&lt;/SPAN&gt; &lt;SPAN class=""&gt;proxy_port=&lt;/SPAN&gt;&lt;SPAN&gt;"" &lt;/SPAN&gt;&lt;SPAN class=""&gt;url=&lt;A href="https://internal-onyxquals-738401111.eu-west-1.elb.amazonaws.com/view/adminLogin.jsp" target="_blank" rel="noopener"&gt;https://internal-onyxquals-738401111.eu-west-1.elb.amazonaws.com/view/adminLogin.jsp&lt;/A&gt;&lt;/SPAN&gt; &lt;SPAN class=""&gt;total_time=&lt;/SPAN&gt;&lt;SPAN&gt;"" &lt;/SPAN&gt;&lt;SPAN class=""&gt;request_time=&lt;/SPAN&gt;&lt;SPAN&gt;"" &lt;/SPAN&gt;&lt;SPAN class=""&gt;timeout=120&lt;/SPAN&gt; &lt;SPAN class=""&gt;response_code=&lt;/SPAN&gt;&lt;SPAN&gt;"" &lt;/SPAN&gt;&lt;SPAN class=""&gt;proxy_type=http&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 11:07:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582235#M13418</guid>
      <dc:creator>jackin</dc:creator>
      <dc:date>2022-01-24T11:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582239#M13419</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239496"&gt;@jackin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if this is your row log, you cannot do anything because the values are missing in the source; it isn't a parsing error.&lt;/P&gt;&lt;P&gt;You could force response_code="504"&amp;nbsp; and response_time=_time-120, something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval response_code=if(timed_out="True",504,response_code), response_time=if(timed_out="True",_time-120,response_code)&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 11:30:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582239#M13419</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-01-24T11:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: URL Monitoring issue</title>
      <link>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582241#M13420</link>
      <description>&lt;P&gt;As I said earlier the add-on starts doing this when the no of tests increase on the hf it's installed. There is no fix to this just a work around only if you know your url is up when response code field is empty&lt;/P&gt;&lt;P&gt;|eval response_code = if ( response_code= "", "200" , response_code)&lt;/P&gt;&lt;P&gt;This will update empty response code as 200 else will keep what ever response code is there in actual event.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 11:40:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/URL-Monitoring-issue/m-p/582241#M13420</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-24T11:40:30Z</dc:date>
    </item>
  </channel>
</rss>

