<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search help - reporting backup status in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-help-reporting-backup-status/m-p/15017#M1725</link>
    <description>&lt;P&gt;Some recommendations below, but sticking with the way you're doing it for now, i think this will give you what you're looking for: &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;"EventCode=8019" OR " 8019 " starthoursago="24" | eval status = if(_raw LIKE successfully, "OK", "Backup Failed") | stats first(_time) as time first(status) as status by host | fields time host status&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;recommendations: &lt;/P&gt;

&lt;P&gt;I recommend creating a field extraction to extract the eventCode properly. This will allow you to operate on it more easily.   ie eventCode=8019   instead of the slower and more cumbersome "EventCode=8019" OR " 8019 ".   It'll also allow you to do more interesting reporting on eventCode values.&lt;/P&gt;

&lt;P&gt;I also recommend not using the old 3.X time term syntax of 'starthoursago=24' in the search language. In 4.0 and 4.1 this corresponds to setting the earliest argument to "-24h" or "-24h@h", depending.&lt;BR /&gt;
If you use the old legacy arguments like this, the UI will nag you with blue messages everywhere. &lt;/P&gt;

&lt;P&gt;and lastly,  "fields + host"  and "fields host" are synonymous in 4.1.  There used to be a difference but its gone now. &lt;/P&gt;</description>
    <pubDate>Fri, 18 Jun 2010 04:26:18 GMT</pubDate>
    <dc:creator>sideview</dc:creator>
    <dc:date>2010-06-18T04:26:18Z</dc:date>
    <item>
      <title>Search help - reporting backup status</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-help-reporting-backup-status/m-p/15016#M1724</link>
      <description>&lt;P&gt;We have many hosts running backups every night and report back if they are successful or not.  I would like to simplify the report the search produces so that it easier to read.  What should I change in my search to get my preferred output?&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;

&lt;P&gt;Splunk events of both types of events:&lt;/P&gt;

&lt;P&gt;Jun 2 21:04:55 xx.xx.13.123 Jun 2 21:04:52 xxx-app-03 ntbackup[info] 8019 End Operation: The operation was successfully completed. Consult the backup report for more details.&lt;/P&gt;

&lt;P&gt;Jun 2 21:04:52 xx.xx.13.172 Jun 2 21:04:48 xxx-2 ntbackup[error] 8019 Warnings or errors were encountered.&lt;/P&gt;

&lt;P&gt;Current Search we are using:&lt;/P&gt;

&lt;P&gt;"EventCode=8019" OR " 8019 " starthoursago="24" | fields + host | eval status = if(_raw LIKE successfully, "OK", "Backup Failed")&lt;/P&gt;

&lt;P&gt;Current Output:&lt;/P&gt;

&lt;P&gt;_time host status _raw 1275451893 xx.xx.13.20  Backup Failed&lt;/P&gt;

&lt;P&gt;Jun 1 23:11:33 xx.xx.13.20 Jun 1 23:11:31 host-PROC ntbackup[info] 8019 End Operation: The operation was successfully completed. Consult the backup report for more details.&lt;/P&gt;

&lt;P&gt;Preferred output:&lt;/P&gt;

&lt;P&gt;Date Time Host status&lt;/P&gt;

&lt;P&gt;6/1/2010 23:11 host-PROC OK&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2010 00:47:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-help-reporting-backup-status/m-p/15016#M1724</guid>
      <dc:creator>Jaci</dc:creator>
      <dc:date>2010-06-08T00:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: Search help - reporting backup status</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-help-reporting-backup-status/m-p/15017#M1725</link>
      <description>&lt;P&gt;Some recommendations below, but sticking with the way you're doing it for now, i think this will give you what you're looking for: &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;"EventCode=8019" OR " 8019 " starthoursago="24" | eval status = if(_raw LIKE successfully, "OK", "Backup Failed") | stats first(_time) as time first(status) as status by host | fields time host status&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;recommendations: &lt;/P&gt;

&lt;P&gt;I recommend creating a field extraction to extract the eventCode properly. This will allow you to operate on it more easily.   ie eventCode=8019   instead of the slower and more cumbersome "EventCode=8019" OR " 8019 ".   It'll also allow you to do more interesting reporting on eventCode values.&lt;/P&gt;

&lt;P&gt;I also recommend not using the old 3.X time term syntax of 'starthoursago=24' in the search language. In 4.0 and 4.1 this corresponds to setting the earliest argument to "-24h" or "-24h@h", depending.&lt;BR /&gt;
If you use the old legacy arguments like this, the UI will nag you with blue messages everywhere. &lt;/P&gt;

&lt;P&gt;and lastly,  "fields + host"  and "fields host" are synonymous in 4.1.  There used to be a difference but its gone now. &lt;/P&gt;</description>
      <pubDate>Fri, 18 Jun 2010 04:26:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-help-reporting-backup-status/m-p/15017#M1725</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2010-06-18T04:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: Search help - reporting backup status</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-help-reporting-backup-status/m-p/15018#M1726</link>
      <description>&lt;P&gt;Thank you for your help Nick!!&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jun 2010 04:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-help-reporting-backup-status/m-p/15018#M1726</guid>
      <dc:creator>Jaci</dc:creator>
      <dc:date>2010-06-18T04:59:57Z</dc:date>
    </item>
  </channel>
</rss>

