<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do you find true or false value in the following string? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427073#M167000</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have to find the value of true or false from the following string in logfile. Below are 2 strings with either a true or false value. I just want to find a string with a false value and create an alert. &lt;/P&gt;

&lt;P&gt;How do I achieve this?&lt;/P&gt;

&lt;P&gt;batchId ==&amp;gt;9459a2b3-871c-4f1b-aece-feb905121b3f==false&lt;BR /&gt;
batchId ==&amp;gt;14c86ffd-2ae5-4848-995e-6923485c9ed6==true&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 16 Oct 2018 07:10:32 GMT</pubDate>
    <dc:creator>abhishekgandhe</dc:creator>
    <dc:date>2018-10-16T07:10:32Z</dc:date>
    <item>
      <title>How do you find true or false value in the following string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427073#M167000</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have to find the value of true or false from the following string in logfile. Below are 2 strings with either a true or false value. I just want to find a string with a false value and create an alert. &lt;/P&gt;

&lt;P&gt;How do I achieve this?&lt;/P&gt;

&lt;P&gt;batchId ==&amp;gt;9459a2b3-871c-4f1b-aece-feb905121b3f==false&lt;BR /&gt;
batchId ==&amp;gt;14c86ffd-2ae5-4848-995e-6923485c9ed6==true&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 07:10:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427073#M167000</guid>
      <dc:creator>abhishekgandhe</dc:creator>
      <dc:date>2018-10-16T07:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: How do you find true or false value in the following string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427074#M167001</link>
      <description>&lt;P&gt;Searching for a specific string in Splunk is a matter of specifying that string in your query.  For example, &lt;CODE&gt;index=foo "false" | ...&lt;/CODE&gt; will return all events with "false" in them.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 11:11:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427074#M167001</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-10-16T11:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do you find true or false value in the following string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427075#M167002</link>
      <description>&lt;P&gt;My mistake. I should have given full requirement.&lt;/P&gt;

&lt;P&gt;I want to first find the batchID and then corresponding true/false value for it.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 02:33:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427075#M167002</guid>
      <dc:creator>abhishekgandhe</dc:creator>
      <dc:date>2018-10-17T02:33:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do you find true or false value in the following string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427076#M167003</link>
      <description>&lt;P&gt;Hi @abhishekgandhe ,&lt;/P&gt;

&lt;P&gt;Can you share a few sample events?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 04:05:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427076#M167003</guid>
      <dc:creator>MousumiChowdhur</dc:creator>
      <dc:date>2018-10-17T04:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do you find true or false value in the following string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427077#M167004</link>
      <description>&lt;P&gt;Here are some logs&lt;/P&gt;

&lt;P&gt;{"message":[{"raw":"Lab checkRcReady for &lt;STRONG&gt;batchId ==&amp;gt;2d465022-fb3a-4584-a9c4-6cec867e6694==true&lt;/STRONG&gt; :: Output Quality 41.6289592760181%","severityLevel":"Informational","timestamp":"2018-10-17T09:30:47+00:00","sourceType":"LOGBack","loggerName":"com.honeywell.pmt.cps.service.JobformationServiceImpl","level":"INFO","threadName":"pool-29-thread-1"}],"internal":{"data":{"id":"5665ef35-d1ef-11e8-9c0f-9b51e6fd477d","documentVersion":"1.61"}},"context":{"data":{"eventTime":"2018-10-17T09:30:47.923Z","isSynthetic":false,"samplingRate":100.0},"device":{"id":"e5fae3de5734","type":"PC","osVersion":"Linux","roleInstance":"e5fae3de5734","deviceName":"Other","deviceModel":"Other","locale":"en-US","browser":"Apache-HttpClient","browserVersion":"Apache-HttpClient 4.5","screenResolution":{}},"user":{"isAuthenticated":false},"session":{"isFirst":false},"operation":{},"location":{"clientip":"0.0.0.0","continent":"North America","country":"United States","province":"Virginia","city":"Boydton"},"custom":{"dimensions":[{"LoggerName":"com.honeywell.pmt.cps.service.JobformationServiceImpl"},{"LoggingLevel":"INFO"},{"SourceType":"LOGBack"},{"TimeStamp":"Wed, 17 Oct 2018 09:30:47 GMT"},{"systemGuid":"9516e36a-e5e9-4ec5-a449-edcaeb5f227f"},{"pointId":"fi_12101_01.pv_ag"},{"ThreadName":"pool-29-thread-1"},{"endTime":"1539232140000"}]}}}&lt;BR /&gt;
... 3 lines omitted ...&lt;BR /&gt;
{"message":[{"raw":"Critical-Lab checkRcReady for &lt;STRONG&gt;batchId ==&amp;gt;16cfe3ea-52be-4017-b2b2-aedbb360d150==true&lt;/STRONG&gt; :: Output Quality 0.0%","severityLevel":"Informational","timestamp":"2018-10-17T09:30:49+00:00","sourceType":"LOGBack","loggerName":"com.honeywell.pmt.cps.service.JobformationServiceImpl","level":"INFO","threadName":"pool-29-thread-1"}],"internal":{"data":{"id":"5665ef39-d1ef-11e8-9c0f-9b51e6fd477d","documentVersion":"1.61"}},"context":{"data":{"eventTime":"2018-10-17T09:30:49.321Z","isSynthetic":false,"samplingRate":100.0},"device":{"id":"e5fae3de5734","type":"PC","osVersion":"Linux","roleInstance":"e5fae3de5734","deviceName":"Other","deviceModel":"Other","locale":"en-US","browser":"Apache-HttpClient","browserVersion":"Apache-HttpClient 4.5","screenResolution":{}},"user":{"isAuthenticated":false},"session":{"isFirst":false},"operation":{},"location":{"clientip":"0.0.0.0","continent":"North America","country":"United States","province":"Virginia","city":"Boydton"},"custom":{"dimensions":[{"LoggerName":"com.honeywell.pmt.cps.service.JobformationServiceImpl"},{"LoggingLevel":"INFO"},{"SourceType":"LOGBack"},{"TimeStamp":"Wed, 17 Oct 2018 09:30:49 GMT"},{"systemGuid":"9516e36a-e5e9-4ec5-a449-edcaeb5f227f"},{"pointId":"fi_12101_01.pv_ag"},{"ThreadName":"pool-29-thread-1"},{"endTime":"1539239340000"}]}}}&lt;BR /&gt;
... 9 lines omitted ...&lt;BR /&gt;
{"message":[{"raw":"Critical-Lab checkRcReady for &lt;STRONG&gt;batchId ==&amp;gt;85d82866-11be-447d-a06c-5ed1bb727a13==true&lt;/STRONG&gt; :: Output Quality 0.0%","severityLevel":"Informational","timestamp":"2018-10-17T09:30:52+00:00","sourceType":"LOGBack","loggerName":"com.honeywell.pmt.cps.service.JobformationServiceImpl","level":"INFO","threadName":"pool-29-thread-1"}],"internal":{"data":{"id":"598e0a35-d1ef-11e8-8b3a-4b8260d9fc0d","documentVersion":"1.61"}},"context":{"data":{"eventTime":"2018-10-17T09:30:52.616Z","isSynthetic":false,"samplingRate":100.0},"device":{"id":"e5fae3de5734","type":"PC","osVersion":"Linux","roleInstance":"e5fae3de5734","deviceName":"Other","deviceModel":"Other","locale":"en-US","browser":"Apache-HttpClient","browserVersion":"Apache-HttpClient 4.5","screenResolution":{}},"user":{"isAuthenticated":false},"session":{"isFirst":false},"operation":{},"location":{"clientip":"0.0.0.0","continent":"North America","country":"United States","province":"Virginia","city":"Boydton"},"custom":{"dimensions":[{"LoggerName":"com.honeywell.pmt.cps.service.JobformationServiceImpl"},{"LoggingLevel":"INFO"},{"SourceType":"LOGBack"},{"TimeStamp":"Wed, 17 Oct 2018 09:30:52 GMT"},{"systemGuid":"9516e36a-e5e9-4ec5-a449-edcaeb5f227f"},{"pointId":"fi_12101_01.pv_ag"},{"ThreadName":"pool-29-thread-1"},{"endTime":"1539404040000"}]}}}&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:41:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427077#M167004</guid>
      <dc:creator>abhishekgandhe</dc:creator>
      <dc:date>2020-09-29T21:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: How do you find true or false value in the following string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427078#M167005</link>
      <description>&lt;P&gt;Hi @abhishekgandhe &lt;/P&gt;

&lt;P&gt;You can write a regular expression to extract the batch id and the true/false value. &lt;BR /&gt;
Regex to extract batchId - &lt;CODE&gt;(batchId)\s+\=\=\&amp;gt;(?P&amp;lt;batchID&amp;gt;\d+[^\=]+)&lt;/CODE&gt;&lt;BR /&gt;
Regex to extract true/false value - &lt;CODE&gt;batchId\s+\=\=\&amp;gt;[0-9a-f\-]+\=\=(?P&amp;lt;value&amp;gt;\w+[^\s+]+)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;You can then find out all the events for which &lt;CODE&gt;value="false"&lt;/CODE&gt;, get the respective batchId and set an alert.&lt;BR /&gt;
Let me know if that works for you.&lt;/P&gt;

&lt;P&gt;Thank You!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 11:24:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427078#M167005</guid>
      <dc:creator>MousumiChowdhur</dc:creator>
      <dc:date>2018-10-17T11:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: How do you find true or false value in the following string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427079#M167006</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | rex "batchId\s==&amp;gt;(?&amp;lt;batchId&amp;gt;[^=]+)==(?&amp;lt;batchIdBoolean&amp;gt;\w+)" | ...
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 18 Oct 2018 11:56:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-find-true-or-false-value-in-the-following-string/m-p/427079#M167006</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-10-18T11:56:19Z</dc:date>
    </item>
  </channel>
</rss>

