<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic file manipulation for custom logs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/file-manipulation-for-custom-logs/m-p/55382#M13511</link>
    <description>&lt;P&gt;I have a custom log file format that i am importing via a windows forwarder.  In it there are a number of fields related to configuration items and at the bottom is a summation of all the non-compliant items&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;file=abc&amp;lt;date&amp;gt;.log
hostname=abc
section1=pass
section2=fail
section3=pass
totalFailed=1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;There could be multiple files for the same hostname (havent changed it to ignore non-new files)
I would like to have an output that shows the latest file by hostname and the value for the field totalFailed.  There will be multiple files from different hostnames and i would like the most recent file from each host to show the line of total failed items.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;hostA | file | totalFailed
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;As a bonus point, how would i colorize (red) any values of totalFailed if its non-zero?
I would eventually like to extend this to a dashboard that shows a single value image of all non-compliant hosts (red&amp;gt;0) and all compliant hosts (green=0).  I would imagine i need this to be a parameterized search to return a single value and the hostname to label it.  But first things first, I tried using&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | stats max(file) by hostname
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;but that gets me a count of the files for the latest hostname.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| top limit=1 file by hostname
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;gets me the same thing i believe.&lt;/P&gt;

&lt;P&gt;Any suggestions on how to do this?&lt;/P&gt;</description>
    <pubDate>Tue, 08 Mar 2011 11:05:39 GMT</pubDate>
    <dc:creator>EricPartington</dc:creator>
    <dc:date>2011-03-08T11:05:39Z</dc:date>
    <item>
      <title>file manipulation for custom logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-manipulation-for-custom-logs/m-p/55382#M13511</link>
      <description>&lt;P&gt;I have a custom log file format that i am importing via a windows forwarder.  In it there are a number of fields related to configuration items and at the bottom is a summation of all the non-compliant items&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;file=abc&amp;lt;date&amp;gt;.log
hostname=abc
section1=pass
section2=fail
section3=pass
totalFailed=1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;There could be multiple files for the same hostname (havent changed it to ignore non-new files)
I would like to have an output that shows the latest file by hostname and the value for the field totalFailed.  There will be multiple files from different hostnames and i would like the most recent file from each host to show the line of total failed items.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;hostA | file | totalFailed
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;As a bonus point, how would i colorize (red) any values of totalFailed if its non-zero?
I would eventually like to extend this to a dashboard that shows a single value image of all non-compliant hosts (red&amp;gt;0) and all compliant hosts (green=0).  I would imagine i need this to be a parameterized search to return a single value and the hostname to label it.  But first things first, I tried using&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; | stats max(file) by hostname
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;but that gets me a count of the files for the latest hostname.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| top limit=1 file by hostname
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;gets me the same thing i believe.&lt;/P&gt;

&lt;P&gt;Any suggestions on how to do this?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2011 11:05:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-manipulation-for-custom-logs/m-p/55382#M13511</guid>
      <dc:creator>EricPartington</dc:creator>
      <dc:date>2011-03-08T11:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: file manipulation for custom logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/file-manipulation-for-custom-logs/m-p/55383#M13512</link>
      <description>&lt;P&gt;An update, I changed this to a monitor and now import then entire file and create my fields and do the magic that way.  Problem solved&lt;/P&gt;</description>
      <pubDate>Sun, 13 Mar 2011 00:59:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/file-manipulation-for-custom-logs/m-p/55383#M13512</guid>
      <dc:creator>EricPartington</dc:creator>
      <dc:date>2011-03-13T00:59:13Z</dc:date>
    </item>
  </channel>
</rss>

