<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: trying to generate an alert but  The problem is that the logs are different in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511656#M143456</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Thank you. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What I saw when executing it is that it brings me only values ​​of those 3 logs, specify what variables I wanted to exit. But it doesn't analyze other logs&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jul 2020 23:04:33 GMT</pubDate>
    <dc:creator>yeisonv</dc:creator>
    <dc:date>2020-07-29T23:04:33Z</dc:date>
    <item>
      <title>trying to generate an alert but  The problem is that the logs are different</title>
      <link>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511545#M143405</link>
      <description>&lt;P&gt;Good morning, I am trying to generate an alert for productive applications when they are in "debug" mode&lt;/P&gt;&lt;P&gt;The problem is that the logs are different.&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i search "index=wls sourcetype=wls_managedserver "debug" | stats count by host"&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;logically it lists the hosts that meet the condition in debug mode.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would need to generate an alert to send me which hosts have the app in debug mode, but at the same time to send me only a trace of that search by email&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ó&amp;nbsp;extract the fields but it is more difficult because they are different&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Host= W1422&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cluster= qa.3.3_man05&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;app=&amp;nbsp;app.userdown or&amp;nbsp;[&lt;SPAN class="t"&gt;appwork.consumer.serviceTaskExecutorBackedUpQueueConsumer-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;149&lt;/SPAN&gt;]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;log examples:&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;####&lt;/SPAN&gt;&amp;lt;&lt;SPAN class="t"&gt;Jul&lt;/SPAN&gt; &lt;SPAN class="t"&gt;29&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;2020&lt;/SPAN&gt; &lt;SPAN class="t"&gt;12:07:28&lt;/SPAN&gt; &lt;SPAN class="t"&gt;PM&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ART&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;Notice&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;Stdout&lt;/SPAN&gt;&amp;gt; &amp;lt;W1422&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;qa3.3_man05&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;mq.task.executor-1&lt;/SPAN&gt;&amp;gt; &amp;lt;&amp;lt;&lt;SPAN class="t"&gt;WLS&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Kernel&lt;/SPAN&gt;&amp;gt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;1596035248169&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;BEA-000000&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;2020/07/29&lt;/SPAN&gt; &lt;SPAN class="t"&gt;12:07:28.169&lt;/SPAN&gt; [&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;DEBUG&lt;/SPAN&gt;&lt;/SPAN&gt;] [&lt;SPAN class="t"&gt;mq.task.executor-1&lt;/SPAN&gt;] [&lt;SPAN class="t"&gt;appwork.consumer.serviceTaskExecutorBackedUpQueueConsumer-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;149&lt;/SPAN&gt;] &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;No&lt;/SPAN&gt; &lt;SPAN class="t"&gt;hay&lt;/SPAN&gt; &lt;SPAN class="t"&gt;mensajes&lt;/SPAN&gt; &lt;SPAN class="t"&gt;en&lt;/SPAN&gt; &lt;SPAN class="t"&gt;la&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cola&lt;/SPAN&gt;&amp;gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="shared-eventsviewer-list-body-row-selectedfields"&gt;&lt;UL class="condensed-selected-fields"&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;host =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;W1422&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;source =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value"&gt;&lt;A title="/logs/qa3_domain3/qa3.3_man05_yyyy-MM-dd.log" href="https://splunkdqh.redlink.com.ar/en-US/app/Middleware_app/search?earliest=-15m&amp;amp;latest=now&amp;amp;q=search%20index%3Dwls%20sourcetype%3Dwls_managedserver%20%22debug%22%20%20host%3DLNK1398&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1596035250.457878#" target="_blank" rel="noopener"&gt;/logs/qa3_domain3/qa3.3_man05_yyyy-MM-dd.log&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;sourcetype =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value a"&gt;&lt;A title="wls_managedserver" href="https://splunkdqh.redlink.com.ar/en-US/app/Middleware_app/search?earliest=-15m&amp;amp;latest=now&amp;amp;q=search%20index%3Dwls%20sourcetype%3Dwls_managedserver%20%22debug%22%20%20host%3DLNK1398&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1596035250.457878#" target="_blank" rel="noopener"&gt;wls_managedserver&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;####&lt;/SPAN&gt;&amp;lt;&lt;SPAN class="t"&gt;Jul&lt;/SPAN&gt; &lt;SPAN class="t"&gt;29&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;2020&lt;/SPAN&gt; &lt;SPAN class="t"&gt;12:09:16&lt;/SPAN&gt; &lt;SPAN class="t"&gt;PM&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ART&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;Notice&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;Stdout&lt;/SPAN&gt;&amp;gt; &amp;lt;W1522&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;qa3.3_cl6_man01&lt;/SPAN&gt;&amp;gt; &amp;lt;app.userdown&amp;gt; &amp;lt;&amp;lt;&lt;SPAN class="t"&gt;WLS&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Kernel&lt;/SPAN&gt;&amp;gt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;1596035356838&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;BEA-000000&lt;/SPAN&gt;&amp;gt; &amp;lt;[&lt;SPAN class="t"&gt;29/07/2020&lt;/SPAN&gt; &lt;SPAN class="t"&gt;12:09&lt;/SPAN&gt;] &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;DEBUG&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;MonitoringManager.getSourceProcessor&lt;/SPAN&gt;() &lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&amp;gt; &lt;SPAN class="t"&gt;Verificando&lt;/SPAN&gt; &lt;SPAN class="t"&gt;processor&lt;/SPAN&gt; &lt;SPAN class="t"&gt;para:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;javax.jms.ExceptionListener&lt;/SPAN&gt; &lt;SPAN class="t"&gt;contra&lt;/SPAN&gt; &lt;SPAN class="t"&gt;el&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tipo&lt;/SPAN&gt; &lt;SPAN class="t"&gt;.persistence&lt;/SPAN&gt;&amp;gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="shared-eventsviewer-list-body-row-selectedfields"&gt;&lt;UL class="condensed-selected-fields"&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;host =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value a"&gt;&lt;A title="LNK2400" href="https://splunkdqh.redlink.com.ar/en-US/app/Middleware_app/search?earliest=-15m&amp;amp;latest=now&amp;amp;q=search%20index%3Dwls%20sourcetype%3Dwls_managedserver%20%22debug%22%20%20host%3DLNK2400&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1596035363.457963#" target="_blank" rel="noopener"&gt;W1522&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;source =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value"&gt;&lt;A title="/logs/qa3_domain3/qa3.3_cl6_man01p_yyyy-MM-dd.log" href="https://splunkdqh.redlink.com.ar/en-US/app/Middleware_app/search?earliest=-15m&amp;amp;latest=now&amp;amp;q=search%20index%3Dwls%20sourcetype%3Dwls_managedserver%20%22debug%22%20%20host%3DLNK2400&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1596035363.457963#" target="_blank" rel="noopener"&gt;/logs/qa3_domain3/qa3.3_cl6_man01p_yyyy-MM-dd.log&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="field"&gt;sourcetype =&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="field-value a"&gt;&lt;A title="wls_managedserver" href="https://splunkdqh.redlink.com.ar/en-US/app/Middleware_app/search?earliest=-15m&amp;amp;latest=now&amp;amp;q=search%20index%3Dwls%20sourcetype%3Dwls_managedserver%20%22debug%22%20%20host%3DLNK2400&amp;amp;display.page.search.mode=smart&amp;amp;dispatch.sample_ratio=1&amp;amp;display.page.search.tab=events&amp;amp;display.general.type=events&amp;amp;sid=1596035363.457963#" target="_blank" rel="noopener"&gt;wls_managedserver&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class="t"&gt;####&lt;/SPAN&gt;&amp;lt;&lt;SPAN class="t"&gt;Jul&lt;/SPAN&gt; &lt;SPAN class="t"&gt;29&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;2020&lt;/SPAN&gt; &lt;SPAN class="t"&gt;12:10:01&lt;/SPAN&gt; &lt;SPAN class="t"&gt;PM&lt;/SPAN&gt; &lt;SPAN class="t"&gt;ART&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;Notice&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;Stdout&lt;/SPAN&gt;&amp;gt; &amp;lt;W0188&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;desa5.3_cl6_man01&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;org.springframework.scheduling.quartz.SchedulerFactoryBean#0_Worker-7&lt;/SPAN&gt;&amp;gt; &amp;lt;&amp;lt;&lt;SPAN class="t"&gt;WLS&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Kernel&lt;/SPAN&gt;&amp;gt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;1596035401281&lt;/SPAN&gt;&amp;gt; &amp;lt;&lt;SPAN class="t"&gt;BEA-000000&lt;/SPAN&gt;&amp;gt; &amp;lt;[&lt;SPAN class="t"&gt;29/07/2020&lt;/SPAN&gt; &lt;SPAN class="t"&gt;12:10&lt;/SPAN&gt;] &lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;DEBUG&lt;/SPAN&gt;&lt;/SPAN&gt; &lt;SPAN class="t"&gt;SqlStatementLogger.logStatement&lt;/SPAN&gt;() &lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if anyone can help me&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 15:18:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511545#M143405</guid>
      <dc:creator>yeisonv</dc:creator>
      <dc:date>2020-07-29T15:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: trying to generate an alert but  The problem is that the logs are different</title>
      <link>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511578#M143412</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;If those three lines are all WLS messages which you have, then you could try this.&lt;/P&gt;&lt;LI-CODE lang="java"&gt;index=_internal | head 1
| eval _raw="####&amp;lt;Jul 29, 2020 12:07:28 PM ART&amp;gt; &amp;lt;Notice&amp;gt; &amp;lt;Stdout&amp;gt; &amp;lt;W1422&amp;gt; &amp;lt;qa3.3_man05&amp;gt; &amp;lt;mq.task.executor-1&amp;gt; &amp;lt;&amp;lt;WLS Kernel&amp;gt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;1596035248169&amp;gt; &amp;lt;BEA-000000&amp;gt; &amp;lt;2020/07/29 12:07:28.169 [DEBUG] [mq.task.executor-1] [appwork.consumer.serviceTaskExecutorBackedUpQueueConsumer- 149] - No hay mensajes en la cola&amp;gt;
####&amp;lt;Jul 29, 2020 12:09:16 PM ART&amp;gt; &amp;lt;Notice&amp;gt; &amp;lt;Stdout&amp;gt; &amp;lt;W1522&amp;gt; &amp;lt;qa3.3_cl6_man01&amp;gt; &amp;lt;app.userdown&amp;gt; &amp;lt;&amp;lt;WLS Kernel&amp;gt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;1596035356838&amp;gt; &amp;lt;BEA-000000&amp;gt; &amp;lt;[29/07/2020 12:09] DEBUG MonitoringManager.getSourceProcessor() -&amp;gt; Verificando processor para: javax.jms.ExceptionListener contra el tipo .persistence&amp;gt;
####&amp;lt;Jul 29, 2020 12:10:01 PM ART&amp;gt; &amp;lt;Notice&amp;gt; &amp;lt;Stdout&amp;gt; &amp;lt;W0188&amp;gt; &amp;lt;desa5.3_cl6_man01&amp;gt; &amp;lt;org.springframework.scheduling.quartz.SchedulerFactoryBean#0_Worker-7&amp;gt; &amp;lt;&amp;lt;WLS Kernel&amp;gt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;&amp;gt; &amp;lt;1596035401281&amp;gt; &amp;lt;BEA-000000&amp;gt; &amp;lt;[29/07/2020 12:10] DEBUG SqlStatementLogger.logStatement() -&amp;gt;" 
| multikv noheader=t
| rename COMMENT as "prepare sample data"
| rex "(\&amp;lt;[^&amp;gt;]+&amp;gt; ){3}\&amp;lt;(?&amp;lt;Host&amp;gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?&amp;lt;Cluster&amp;gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?&amp;lt;App&amp;gt;[^&amp;gt;]+)&amp;gt;.*BEA-000000&amp;gt;\s&amp;lt;(?&amp;lt;Message&amp;gt;[^&amp;gt;]+)&amp;gt;"&lt;/LI-CODE&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 16:39:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511578#M143412</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-29T16:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: trying to generate an alert but  The problem is that the logs are different</title>
      <link>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511627#M143436</link>
      <description>&lt;P&gt;&lt;SPAN&gt;thank you very much for taking the time to help me&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;The problem is that in production we have more than 60 productive applications and they are always changing. I'm trying to identify when they change the app to "debug" mode and thus generate an alert&lt;/P&gt;&lt;P&gt;so&amp;nbsp;&lt;SPAN&gt;When executing this&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;index=wls sourcetype=wls_managedserver "debug" | stats count by host&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It shows me the hosts where the word "Debug" is, but I see many events because the app writes the same thing several times in the log. Is there a way to be able to list the hosts that send me 1 event per hosts by email?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 20:29:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511627#M143436</guid>
      <dc:creator>yeisonv</dc:creator>
      <dc:date>2020-07-29T20:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: trying to generate an alert but  The problem is that the logs are different</title>
      <link>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511640#M143445</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;try to add the next to the end of previous example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="java"&gt;...
| rex field=Message "\[?\d+\/\d+\/\d+\s+\d+:\d+(:\d+\.\d+)?\]?\s+\[?(?&amp;lt;logLevel&amp;gt;[^\s\]]+)\]?"
| where logLevel = "DEBUG"
| stats values(Message) as Messages by logLevel,Host&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and then define alert as you need-&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 21:58:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511640#M143445</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-29T21:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: trying to generate an alert but  The problem is that the logs are different</title>
      <link>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511656#M143456</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What I saw when executing it is that it brings me only values ​​of those 3 logs, specify what variables I wanted to exit. But it doesn't analyze other logs&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2020 23:04:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511656#M143456</guid>
      <dc:creator>yeisonv</dc:creator>
      <dc:date>2020-07-29T23:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: trying to generate an alert but  The problem is that the logs are different</title>
      <link>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511746#M143492</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;have you tried it like this:&lt;/P&gt;&lt;LI-CODE lang="java"&gt;index=wls sourcetype=wls_managedserver "debug" 
| rex "(\&amp;lt;[^&amp;gt;]+&amp;gt; ){3}\&amp;lt;(?&amp;lt;Host&amp;gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?&amp;lt;Cluster&amp;gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?&amp;lt;App&amp;gt;[^&amp;gt;]+)&amp;gt;.*BEA-000000&amp;gt;\s&amp;lt;(?&amp;lt;Message&amp;gt;[^&amp;gt;]+)&amp;gt;"
| rex field=Message "\[?\d+\/\d+\/\d+\s+\d+:\d+(:\d+\.\d+)?\]?\s+\[?(?&amp;lt;logLevel&amp;gt;[^\s\]]+)\]?"
| where logLevel = "DEBUG"
| stats values(Message) as Messages by logLevel,Host&lt;/LI-CODE&gt;&lt;P&gt;This should found all nodes if those format is same.&lt;/P&gt;&lt;P&gt;One possible change can be that BEA-000000 which should change to BEA-[^\&amp;gt;]+ This should match also to some error messages not only informative.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 12:58:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511746#M143492</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-30T12:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: trying to generate an alert but  The problem is that the logs are different</title>
      <link>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511757#M143495</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you very much, He had put together something similar. if i want to send 1 single event found by host?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;When I run the query I have many events per host but I would like to send 1 even by email&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 13:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511757#M143495</guid>
      <dc:creator>yeisonv</dc:creator>
      <dc:date>2020-07-30T13:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: trying to generate an alert but  The problem is that the logs are different</title>
      <link>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511794#M143502</link>
      <description>&lt;P&gt;thanks I was able to solve with "dedup"&lt;BR /&gt;&lt;BR /&gt;index=wls sourcetype=wls_managedserver "debug" OR "DEBUG"&lt;BR /&gt;| rex "(\&amp;lt;[^&amp;gt;]+&amp;gt; ){3}\&amp;lt;(?&amp;lt;Host&amp;gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?&amp;lt;Cluster&amp;gt;[^&amp;gt;]+)&amp;gt;\s+&amp;lt;(?&amp;lt;App&amp;gt;[^&amp;gt;]+)&amp;gt;.*BEA-000000&amp;gt;\s&amp;lt;(?&amp;lt;Message&amp;gt;[^&amp;gt;]+)&amp;gt;"&lt;BR /&gt;| rex field=Message "\[?\d+\/\d+\/\d+\s+\d+:\d+(:\d+\.\d+)?\]?\s+\[?(?&amp;lt;logLevel&amp;gt;[^\s\]]+)\]?"&lt;BR /&gt;| dedup host&lt;BR /&gt;| where logLevel = "DEBUG"&lt;BR /&gt;| stats values(Message) as Messages by logLevel, Host, Cluster&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im happy thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2020 16:35:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/trying-to-generate-an-alert-but-The-problem-is-that-the-logs-are/m-p/511794#M143502</guid>
      <dc:creator>yeisonv</dc:creator>
      <dc:date>2020-07-30T16:35:55Z</dc:date>
    </item>
  </channel>
</rss>

