<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to alert host stop on failover paired hosts in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-alert-host-stop-on-failover-paired-hosts/m-p/587890#M204740</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233940"&gt;@vl951f&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you could add a column in the lookup containing an ID for each pair, you could use it for the check.&lt;/P&gt;&lt;P&gt;In other words, if the the new column is called pair_ID, you could run something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=summary search_name=feed_status
| lookup paired_host.csv Host_primary AS Host_name OUTPUT Host_secondary pair_ID
| lookup paired_host.csv Host_secondary AS Host_name OUTPUT Host_primary pair_ID
| stats dc(Host_name) AS dc_Host_name values(Host_primary) AS Host_Primary values(Host_secondary) AS Host_secondary BY pair_ID
| where dc_Host_name =2&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Mar 2022 16:27:08 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-03-07T16:27:08Z</dc:date>
    <item>
      <title>How to alert host stop on failover paired hosts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-alert-host-stop-on-failover-paired-hosts/m-p/587871#M204735</link>
      <description>&lt;P&gt;I have host stop event logged in a summary index&lt;/P&gt;&lt;P&gt;Index=summary search_name=feed_status&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="90"&gt;&lt;P&gt;Host_name&lt;/P&gt;&lt;/TD&gt;&lt;TD width="96"&gt;&lt;P&gt;Host_status&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="90"&gt;&lt;P&gt;Host1a&lt;/P&gt;&lt;/TD&gt;&lt;TD width="96"&gt;&lt;P&gt;Host_stop&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="90"&gt;&lt;P&gt;Host2b&lt;/P&gt;&lt;/TD&gt;&lt;TD width="96"&gt;&lt;P&gt;Host_stop&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="90"&gt;&lt;P&gt;Host4a&lt;/P&gt;&lt;/TD&gt;&lt;TD width="96"&gt;&lt;P&gt;Host_stop&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="90"&gt;&lt;P&gt;Host1b&lt;/P&gt;&lt;/TD&gt;&lt;TD width="96"&gt;&lt;P&gt;Host_stop&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="90"&gt;&lt;P&gt;Host3a&lt;/P&gt;&lt;/TD&gt;&lt;TD width="96"&gt;&lt;P&gt;Host_stop&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;I also have a lookup table for failover paired hosts.&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="96"&gt;&lt;P&gt;Host_primary&lt;/P&gt;&lt;/TD&gt;&lt;TD width="110"&gt;&lt;P&gt;Host_secondary&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="96"&gt;&lt;P&gt;Host1a&lt;/P&gt;&lt;/TD&gt;&lt;TD width="110"&gt;&lt;P&gt;Host1b&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="96"&gt;&lt;P&gt;Host2a&lt;/P&gt;&lt;/TD&gt;&lt;TD width="110"&gt;&lt;P&gt;Host2b&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="96"&gt;&lt;P&gt;Host3a&lt;/P&gt;&lt;/TD&gt;&lt;TD width="110"&gt;&lt;P&gt;Host3b&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="96"&gt;&lt;P&gt;Host4a&lt;/P&gt;&lt;/TD&gt;&lt;TD width="110"&gt;&lt;P&gt;Host4b&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;I need to generate the host stop alert when both failover paired hosts are stopped.&lt;/P&gt;&lt;P&gt;In this case alerting on Host1a and Host1b stopped.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 15:16:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-alert-host-stop-on-failover-paired-hosts/m-p/587871#M204735</guid>
      <dc:creator>vl951f</dc:creator>
      <dc:date>2022-03-07T15:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to alert host stop on failover paired hosts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-alert-host-stop-on-failover-paired-hosts/m-p/587890#M204740</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233940"&gt;@vl951f&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you could add a column in the lookup containing an ID for each pair, you could use it for the check.&lt;/P&gt;&lt;P&gt;In other words, if the the new column is called pair_ID, you could run something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=summary search_name=feed_status
| lookup paired_host.csv Host_primary AS Host_name OUTPUT Host_secondary pair_ID
| lookup paired_host.csv Host_secondary AS Host_name OUTPUT Host_primary pair_ID
| stats dc(Host_name) AS dc_Host_name values(Host_primary) AS Host_Primary values(Host_secondary) AS Host_secondary BY pair_ID
| where dc_Host_name =2&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 16:27:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-alert-host-stop-on-failover-paired-hosts/m-p/587890#M204740</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-03-07T16:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to alert host stop on failover paired hosts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-alert-host-stop-on-failover-paired-hosts/m-p/587910#M204745</link>
      <description>&lt;P&gt;Hi, Giuseppe:&lt;/P&gt;&lt;P&gt;I added the column pair_ID, ad give it an unique number for each paired host. But "dc_Host_name" is always "1" after run the search.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 19:00:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-alert-host-stop-on-failover-paired-hosts/m-p/587910#M204745</guid>
      <dc:creator>vl951f</dc:creator>
      <dc:date>2022-03-07T19:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to alert host stop on failover paired hosts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-alert-host-stop-on-failover-paired-hosts/m-p/587920#M204751</link>
      <description>&lt;P&gt;It looks like one of the pair_ID is NULL from 2 lookup OUTPUT:&lt;/P&gt;&lt;P&gt;| lookup paired_host.csv Host_primary AS Host_name OUTPUT Host_secondary pair_ID&lt;BR /&gt;| lookup paired_host.csv Host_secondary AS Host_name OUTPUT Host_primary pair_ID&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2022 22:46:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-alert-host-stop-on-failover-paired-hosts/m-p/587920#M204751</guid>
      <dc:creator>vl951f</dc:creator>
      <dc:date>2022-03-07T22:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to alert host stop on failover paired hosts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-alert-host-stop-on-failover-paired-hosts/m-p/587927#M204755</link>
      <description>&lt;P&gt;Hi, Giuseppe&lt;/P&gt;&lt;P&gt;I changed OUTPUT to OUTPUTNEW. It works.&lt;/P&gt;&lt;P&gt;index=summary search_name=feed_status&lt;BR /&gt;| lookup paired_host.csv Host_primary AS Host_name OUTPUTNEW Host_secondary as hostname2 pair_ID as pairid&lt;BR /&gt;| lookup paired_host.csv Host_secondary AS Host_name OUTPUTNEW Host_primary as hostname1 pair_ID as pairid&lt;BR /&gt;| stats dc(Host_name) AS hcount values(hostname1) AS Host_Primary values(hostname2) AS Host_secondary BY pairid&lt;BR /&gt;| where hcount =2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 00:49:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-alert-host-stop-on-failover-paired-hosts/m-p/587927#M204755</guid>
      <dc:creator>vl951f</dc:creator>
      <dc:date>2022-03-08T00:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to alert host stop on failover paired hosts</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-alert-host-stop-on-failover-paired-hosts/m-p/587957#M204764</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233940"&gt;@vl951f&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2022 08:03:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-alert-host-stop-on-failover-paired-hosts/m-p/587957#M204764</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-03-08T08:03:07Z</dc:date>
    </item>
  </channel>
</rss>

