<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search Query for checking the Uptime of Website in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-Query-for-checking-the-Uptime-of-Website/m-p/568445#M198102</link>
    <description>&lt;P&gt;This might be possible with the stats command, transaction command, or in a variety of other ways.&lt;/P&gt;&lt;P&gt;What does your data look like?&amp;nbsp; Can you provide a few rows of that raw data as you see it in Splunk?&lt;/P&gt;</description>
    <pubDate>Fri, 24 Sep 2021 21:02:54 GMT</pubDate>
    <dc:creator>Richfez</dc:creator>
    <dc:date>2021-09-24T21:02:54Z</dc:date>
    <item>
      <title>Search Query for checking the Uptime of Website</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Query-for-checking-the-Uptime-of-Website/m-p/568187#M198000</link>
      <description>&lt;P&gt;Hi Folks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to check at what time url has been brought up. Url already added in website monitoring. For example if the url was down at 12 PM and it has been brought up at 1 AM this dashboard panel should indicate 1 PM url went up. I want to monitor multiple urls for this scenario. Appreciate your expertise advise.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 05:06:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Query-for-checking-the-Uptime-of-Website/m-p/568187#M198000</guid>
      <dc:creator>sathish2k8</dc:creator>
      <dc:date>2021-09-23T05:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for checking the Uptime of Website</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Query-for-checking-the-Uptime-of-Website/m-p/568445#M198102</link>
      <description>&lt;P&gt;This might be possible with the stats command, transaction command, or in a variety of other ways.&lt;/P&gt;&lt;P&gt;What does your data look like?&amp;nbsp; Can you provide a few rows of that raw data as you see it in Splunk?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2021 21:02:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Query-for-checking-the-Uptime-of-Website/m-p/568445#M198102</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2021-09-24T21:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for checking the Uptime of Website</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Query-for-checking-the-Uptime-of-Website/m-p/568500#M198124</link>
      <description>&lt;P&gt;Firstly, Thanks. Here is the Sample events&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="json-event  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;total_time=18.15&lt;/SPAN&gt; &lt;SPAN class="t"&gt;content_md5=2922faf0859c07df6e2364140f6eee9b&lt;/SPAN&gt; &lt;SPAN class="t"&gt;proxy_server=&lt;/SPAN&gt;"" &lt;SPAN class="t"&gt;proxy_type=http&lt;/SPAN&gt; &lt;SPAN class="t"&gt;timeout=30&lt;/SPAN&gt; &lt;SPAN class="t"&gt;content_sha224=3ab22d7e15f71cc057bbe37b3947ce1e6f8c6458d7fd359dc9a61104&lt;/SPAN&gt; &lt;SPAN class="t"&gt;url=&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;content_size=8524&lt;/SPAN&gt; &lt;SPAN class="t"&gt;title=clust1&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;proxy_port=&lt;/SPAN&gt;"" &lt;SPAN class="t"&gt;request_time=18.15&lt;/SPAN&gt; &lt;SPAN class="t"&gt;response_code=200&lt;/SPAN&gt; &lt;SPAN class="t"&gt;timed_out=False&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="json-event  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;total_time=23.58&lt;/SPAN&gt; &lt;SPAN class="t"&gt;content_md5=2922faf0859c07df6e2364140f6eee9b&lt;/SPAN&gt; &lt;SPAN class="t"&gt;proxy_server=&lt;/SPAN&gt;"" &lt;SPAN class="t"&gt;proxy_type=http&lt;/SPAN&gt; &lt;SPAN class="t"&gt;timeout=30&lt;/SPAN&gt; &lt;SPAN class="t"&gt;content_sha224=3ab22d7e15f71cc057bbe37b3947ce1e6f8c6458d7fd359dc9a61104&lt;/SPAN&gt; &lt;SPAN class="t"&gt;url=&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;content_size=8524&lt;/SPAN&gt; &lt;SPAN class="t"&gt;title=clust2&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;proxy_port=&lt;/SPAN&gt;"" &lt;SPAN class="t"&gt;request_time=23.58&lt;/SPAN&gt; &lt;SPAN class="t"&gt;response_code=200&lt;/SPAN&gt; &lt;SPAN class="t"&gt;timed_out=False&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="json-event  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;total_time=18.86&lt;/SPAN&gt; &lt;SPAN class="t"&gt;content_md5=2922faf0859c07df6e2364140f6eee9b&lt;/SPAN&gt; &lt;SPAN class="t"&gt;proxy_server=&lt;/SPAN&gt;"" &lt;SPAN class="t"&gt;proxy_type=http&lt;/SPAN&gt; &lt;SPAN class="t"&gt;timeout=30&lt;/SPAN&gt; &lt;SPAN class="t"&gt;content_sha224=3ab22d7e15f71cc057bbe37b3947ce1e6f8c6458d7fd359dc9a61104&lt;/SPAN&gt; &lt;SPAN class="t"&gt;url= :6801/&lt;/SPAN&gt; &lt;SPAN class="t"&gt;content_size=8524&lt;/SPAN&gt; &lt;SPAN class="t"&gt;title=Clust2&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="t"&gt;proxy_port=&lt;/SPAN&gt;"" &lt;SPAN class="t"&gt;request_time=18.86&lt;/SPAN&gt; &lt;SPAN class="t"&gt;response_code=200&lt;/SPAN&gt; &lt;SPAN class="t"&gt;timed_out=False&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="shared-eventsviewer-shared-rawfield"&gt;&lt;DIV class="json-event  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;total_time=16.54&lt;/SPAN&gt; &lt;SPAN class="t"&gt;content_md5=2922faf0859c07df6e2364140f6eee9b&lt;/SPAN&gt; &lt;SPAN class="t"&gt;proxy_server=&lt;/SPAN&gt;"" &lt;SPAN class="t"&gt;proxy_type=http&lt;/SPAN&gt; &lt;SPAN class="t"&gt;timeout=30&lt;/SPAN&gt; &lt;SPAN class="t"&gt;content_sha224=3ab22d7e15f71cc057bbe37b3947ce1e6f8c6458d7fd359dc9a61104&lt;/SPAN&gt; &lt;SPAN class="t"&gt;url=&lt;/SPAN&gt; &lt;SPAN class="t"&gt;content_size=8524&lt;/SPAN&gt; &lt;SPAN class="t"&gt;title=Clust4&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;proxy_port=&lt;/SPAN&gt;"" &lt;SPAN class="t"&gt;request_time=16.54&lt;/SPAN&gt; &lt;SPAN class="t"&gt;response_code=200&lt;/SPAN&gt; &lt;SPAN class="t"&gt;timed_out=False&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 00:23:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Query-for-checking-the-Uptime-of-Website/m-p/568500#M198124</guid>
      <dc:creator>sathish2k8</dc:creator>
      <dc:date>2021-09-27T00:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: Search Query for checking the Uptime of Website</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Query-for-checking-the-Uptime-of-Website/m-p/568847#M198258</link>
      <description>&lt;P&gt;Well, that doesn't actually have "website" in it as a field.&lt;/P&gt;&lt;P&gt;Still.&amp;nbsp; If you have that data ingested, and the fields that appear like they should be extracted are (total_time, content_md5, etc...), then ...&lt;/P&gt;&lt;P&gt;OK, so I'm looking even closer at this.&amp;nbsp; How would you, like as a regular person using words in English, describe how you would manually use these 4 rows events to know if the site/page was up at the time?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because, what I see is that it might be more effective to count where field timed_out=True (assumption that's it's value when it's not false).&lt;/P&gt;&lt;P&gt;Or where response_code is 400 or higher (assuming these are http status codes, or similar, and that 300-level ones are redirects.&amp;nbsp; And if this is server code, my guess is problems will be in the error codes at 500 and above in that case.&lt;/P&gt;&lt;P&gt;Either way... for a count of "not timed out" vs. "timed out"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your base search here&amp;gt;
| timechart span=1h count by timed_out&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or maybe you ONLY want the ones that timed_out, this way you can reserve the "by" clause in the timechart for "by title" to split it based on ... well, title.&amp;nbsp; You wanted server or web page, but I don't see that directly so this is my proxy for it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your base search here&amp;gt; timed_out=False
| timechart span=1h count by title&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or maybe only where the status codes are 400+?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;your base search here&amp;gt; status&amp;gt;400
| timechart span=1h count by status&lt;/LI-CODE&gt;&lt;P&gt;There are quite a few options.&lt;/P&gt;&lt;P&gt;A lot of the options are pretty simple ones, leading me to suggest that you take Splunk Fundamentals 1. It's a free 6-10 hour on-line course from Splunk that covers a lot of fairly simple use cases like that, and a lot more.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just search for it in ... oh they've changed things in Splunk education recently.&amp;nbsp; Try here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://education.splunk.com/single-subject-courses" target="_blank"&gt;https://education.splunk.com/single-subject-courses&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and look at the ones that offer "free e-learning".&amp;nbsp; Many of those map to Splunk Fundamentals Part 1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 20:53:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Query-for-checking-the-Uptime-of-Website/m-p/568847#M198258</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2021-09-28T20:53:48Z</dc:date>
    </item>
  </channel>
</rss>

