<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help in a availability calculator in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-prepare-this-availability-calculator/m-p/608279#M211499</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;, thanks a ton for that suggestion, that worked up to an extend.&amp;nbsp;&lt;/P&gt;&lt;P&gt;but there was some challenge. I have attached the output.&lt;/P&gt;&lt;P&gt;Gouping of those dates are not happening.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="output.JPG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20859i38BD45271F4A293A/image-size/large?v=v2&amp;amp;px=999" role="button" title="output.JPG" alt="output.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Expected output :&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-07-29&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-LAG&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;99&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-07-31&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-LAG&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;99&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-07-31&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-ATT&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-08-02&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-ATT&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-08-02&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-LAG&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;98&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-08-03&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-LAG&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;99&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-08-04&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-LAG&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;97&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ALso one more chalenge in removing the blank field, how can i Achieve it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Aug 2022 13:40:32 GMT</pubDate>
    <dc:creator>jerinvarghese</dc:creator>
    <dc:date>2022-08-04T13:40:32Z</dc:date>
    <item>
      <title>How would I prepare this availability calculator?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-prepare-this-availability-calculator/m-p/608257#M211493</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;I need a help in preparing a availability calculator.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Below graph is the requirement.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="target.png" style="width: 463px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20856i4EE0746CC8001E98/image-size/large?v=v2&amp;amp;px=999" role="button" title="target.png" alt="target.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Current output form code below:&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;DESCRIPTION&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;downtime&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;Time&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;QIT-LAG&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;00:00:06&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;2022-07-31&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;QIT-LAG&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;00:00:09&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;2022-07-29&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;QIT-LAG&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;00:00:08&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;2022-07-29&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="33.333333333333336%"&gt;QIT-LAG&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;00:00:10&lt;/TD&gt;
&lt;TD width="33.333333333333336%"&gt;2022-07-29&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Current manual action:&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;1. Am extracting above table in excel,&lt;/P&gt;
&lt;P&gt;2. converting all duration to seconds&lt;/P&gt;
&lt;P&gt;3. grouing it with Day wise.&lt;/P&gt;
&lt;P&gt;4. preparing a percentage loss out of&amp;nbsp;86400 (24*60*60) on each day is the graph.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;CODE:&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=opennms 
| search DESCRIPTION="QIT-LAG"

| transaction nodelabel startswith=eval(Status="DOWN") endswith=eval(Status="UP") keepevicted=true
| eval downtime=if(closed_txn=1,duration,null)
| eval downtime=tostring(downtime, "duration")
| fillnull value="" downtime
| eval Status=if(closed_txn=1,"UP","DOWN")
| rex field=downtime "(?P&amp;lt;downtime&amp;gt;[^.]+)"
| rename _time as Time
| fieldformat Time=strftime(Time,"%Y-%m-%d")
    
| table DESCRIPTION, downtime, Time,&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Challenge:&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;how to convert the current downtime into seconds and also add it with day basis and prpeare a percentage basis graph.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thanks In advance for guidance and help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 14:47:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-prepare-this-availability-calculator/m-p/608257#M211493</guid>
      <dc:creator>jerinvarghese</dc:creator>
      <dc:date>2022-08-04T14:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in a availability calculator</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-prepare-this-availability-calculator/m-p/608269#M211496</link>
      <description>&lt;P&gt;You've done most the work already.&amp;nbsp; Downtime was in seconds before it was converted to a string.&amp;nbsp; Use the &lt;FONT face="courier new,courier"&gt;stats&lt;/FONT&gt; command to group results by day then use &lt;FONT face="courier new,courier"&gt;eval&lt;/FONT&gt; to compute the percentage loss.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=opennms DESCRIPTION="QIT-LAG"
| transaction nodelabel startswith=eval(Status="DOWN") endswith=eval(Status="UP") keepevicted=true
| eval downtime=if(closed_txn=1,duration,null)
| fillnull value="" downtime
| rename _time as Time
| fieldformat Time=strftime(Time,"%Y-%m-%d")
| stats values(DESCRIPTION) as DESCRIPTION, sum(downtime) as total_downtime by Time
| eval pct_loss = (downtime * 100) / 86400
| table DESCRIPTION, downtime, Time, pct_loss&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 12:39:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-prepare-this-availability-calculator/m-p/608269#M211496</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-08-04T12:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in a availability calculator</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-prepare-this-availability-calculator/m-p/608279#M211499</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;, thanks a ton for that suggestion, that worked up to an extend.&amp;nbsp;&lt;/P&gt;&lt;P&gt;but there was some challenge. I have attached the output.&lt;/P&gt;&lt;P&gt;Gouping of those dates are not happening.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="output.JPG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/20859i38BD45271F4A293A/image-size/large?v=v2&amp;amp;px=999" role="button" title="output.JPG" alt="output.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Expected output :&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-07-29&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-LAG&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;99&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-07-31&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-LAG&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;99&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-07-31&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-ATT&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-08-02&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-ATT&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-08-02&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-LAG&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;98&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-08-03&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-LAG&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;99&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;2022-08-04&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;QIT-LAG&lt;/TD&gt;&lt;TD width="33.333333333333336%" height="25px"&gt;97&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ALso one more chalenge in removing the blank field, how can i Achieve it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 13:40:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-prepare-this-availability-calculator/m-p/608279#M211499</guid>
      <dc:creator>jerinvarghese</dc:creator>
      <dc:date>2022-08-04T13:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in a availability calculator</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-would-I-prepare-this-availability-calculator/m-p/608281#M211500</link>
      <description>&lt;P&gt;I'm not sure why that didn't work.&amp;nbsp; Let's try an alternative.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=opennms DESCRIPTION="QIT-LAG"
| transaction nodelabel startswith=eval(Status="DOWN") endswith=eval(Status="UP") keepevicted=true
```Omit "blank" results```
| where closed_txn=1
| bin span=1d _time
| stats values(DESCRIPTION) as DESCRIPTION, sum(downtime) as total_downtime by _time
| eval pct_loss = (total_downtime * 100) / 86400
| rename _time as Time
| fieldformat Time=strftime(Time,"%Y-%m-%d")
| table DESCRIPTION, total_downtime, Time, pct_loss&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 04 Aug 2022 14:10:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-would-I-prepare-this-availability-calculator/m-p/608281#M211500</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-08-04T14:10:15Z</dc:date>
    </item>
  </channel>
</rss>

