<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tempory output storage in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657386#M227067</link>
    <description>&lt;P&gt;I apologize for the confusion. I will try my best to explain it better.&lt;/P&gt;&lt;P&gt;For example,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event_name = pending-transfer&lt;/P&gt;&lt;P&gt;number of task_id's that event_name (pending-transfer) has "3"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below table contains the&amp;nbsp;&lt;STRONG&gt; event_id's &lt;/STRONG&gt;recieved by the "pending-transfer" for different&lt;STRONG&gt; task_id's &lt;/STRONG&gt;at &lt;STRONG&gt;9:30 PM&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Table 1&lt;/EM&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%" height="24px"&gt;&lt;STRONG&gt;Time&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;STRONG&gt;event_name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;STRONG&gt;task_id&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;STRONG&gt;event_id&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;9/4/22 &lt;FONT color="#FF0000"&gt;09:40&lt;/FONT&gt;:39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;1&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;1274856&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;9/4/22 &lt;FONT color="#FF0000"&gt;09:35:&lt;/FONT&gt;39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;2&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;1274856&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;9/4/22 &lt;FONT color="#FF0000"&gt;09:30&lt;/FONT&gt;:39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;3&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;1274817&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At &lt;STRONG&gt;10:00 PM&lt;/STRONG&gt;, there are new&lt;STRONG&gt; event_id's&lt;/STRONG&gt; for different &lt;STRONG&gt;task_id's&lt;/STRONG&gt; for "pending-transfer" as shown below.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Table 2&lt;/EM&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%" height="25px"&gt;&lt;STRONG&gt;Time&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&lt;STRONG&gt;event_name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&lt;STRONG&gt;task_id&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&lt;STRONG&gt;event_id&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;9/4/22 &lt;FONT color="#FF0000"&gt;10:10&lt;/FONT&gt;:39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;1&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;1274856&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;9/4/22 &lt;FONT color="#FF0000"&gt;10:05:&lt;/FONT&gt;39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;2&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;1274748&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;9/4/22 &lt;FONT color="#FF0000"&gt;10:00&lt;/FONT&gt;:39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;3&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;1274902&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For task_id = 1 , there is no change in the event_id (&lt;U&gt;1274856&lt;/U&gt;) for event_id arrived at &lt;STRONG&gt;10:10 PM&lt;/STRONG&gt; compared to the previous event_id at &lt;STRONG&gt;9:40 PM&lt;/STRONG&gt; whereas for other task_id's (task_id=2, task_id=3) there is a change in the event_id.&amp;nbsp; Therefore, alert needs to be generated since there is no change in event_id for task_id=1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, logic needs to check if there is a change in event_id for &lt;STRONG&gt;ALL&lt;/STRONG&gt; task_id's in an event_name and if there is NO change in event_id for &lt;STRONG&gt;ANY&lt;/STRONG&gt; of task_id's in an event_name, then&amp;nbsp; alert needs to be triggered.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will be creating the alert for each event_name by using where clause.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splun query | where event_name = "pending-transfer"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I am not planning to create alert for each specific task_id in the event_name as it lead to so many alerts.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk query | where event_name = "pending-transfer" task_id=1
splunk query | where event_name = "pending-transfer" task_id=2
splunk query | where event_name = "pending-transfer" task_id=3&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;</description>
    <pubDate>Wed, 13 Sep 2023 05:53:42 GMT</pubDate>
    <dc:creator>pukka</dc:creator>
    <dc:date>2023-09-13T05:53:42Z</dc:date>
    <item>
      <title>Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656177#M226640</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I was aware that splunk is very versatile application which allows the users to manipulate the data is many ways.&amp;nbsp; I have extracted the fields of event_name, task_id , event_id. I am trying to create an alert if there is an increment in the event_id for the same task_id &amp;amp; event_name when latest even arrives in the splunk.&lt;/P&gt;&lt;P&gt;For example, event at &lt;FONT color="#FF0000"&gt;3:36:40.395 PM&amp;nbsp;&lt;/FONT&gt;have the task_id which is &lt;FONT color="#FF0000"&gt;3&lt;/FONT&gt;&amp;nbsp; &amp;amp; event_id which is&amp;nbsp;&lt;FONT color="#FF0000"&gt;1223680&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;AND&amp;nbsp; the latest even arrived at&amp;nbsp;&lt;FONT color="#0000FF"&gt;3:52:40.395 PM&amp;nbsp;&lt;/FONT&gt;which have task_id &lt;FONT color="#0000FF"&gt;3&lt;/FONT&gt; &amp;amp; event_id which is&amp;nbsp;&lt;FONT color="#0000FF"&gt;1223681 &lt;/FONT&gt;I am trying to create an alert because for the same task_id (3), event_name (server_state) there is an increment in event_id.&lt;/P&gt;&lt;P&gt;I believe it is only possible if we store the previous event_id in a variable for the same event_name &amp;amp; task_id so that we can compare it with the new event_id. However, we have four different task_id, I am not sure how save the event_id for all those different task_id's. Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log File Explanation:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;8/01/2023 3:52:40.395 PM server_state|3 1123681 5

Date       Timestamp      event_name|task_id event_id random_number&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sample Log file:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;8/01/2023 3:52:40.395 PM  server_state|3 1223681 5
8/01/2023 3:50:40.395 PM  server_state|2 1201257 3
8/01/2023 3:45:40.395 PM  server_state|1 1135465 2
8/01/2023 3:41:40.395 PM  server_state|0 1545468 5
8/01/2023 3:36:40.395 PM  server_state|3 1223680 0
8/01/2023 3:25:40.395 PM  server_state|2 1201256 2
8/01/2023 3:15:40.395 PM  server_state|1 1135464 3
8/01/2023 3:10:40.395 PM  server_state|0 1545467 8&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 00:43:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656177#M226640</guid>
      <dc:creator>pukka</dc:creator>
      <dc:date>2023-08-31T00:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656194#M226644</link>
      <description>&lt;P&gt;If I understand the requirements correctly, an alert sequence is one in which task_id is equal but a later event_id is greater than an earlier one, you can say that conceptually, you need a temporary storage. &amp;nbsp;But like most languages, SPL commands RAM for such transient needs.&lt;/P&gt;&lt;P&gt;From your sample log, is the following what you are looking for?&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;event_name&lt;/TD&gt;&lt;TD&gt;task_id&lt;/TD&gt;&lt;TD&gt;_time&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;event_id&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;server_state&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;2023-08-01 15:41:40.395,2023-08-01 15:10:40.395&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;1545468&lt;/DIV&gt;&lt;DIV class=""&gt;1545467&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;server_state&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;2023-08-01 15:45:40.395,2023-08-01 15:15:40.395&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;1135465&lt;/DIV&gt;&lt;DIV class=""&gt;1135464&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;server_state&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;2023-08-01 15:50:40.395,2023-08-01 15:25:40.395&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;1201257&lt;/DIV&gt;&lt;DIV class=""&gt;1201256&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;server_state&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;2023-08-01 15:52:40.395,2023-08-01 15:36:40.395&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;1223681&lt;/DIV&gt;&lt;DIV class=""&gt;1223680&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;You can achieve this with the following assuming that&amp;nbsp;event_name, task_id, and event_id are already extracted:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats list(_time) as _time list(event_id) as event_id by event_name task_id
| where mvindex(_time, 0) &amp;gt; mvindex(_time, -1) AND mvindex(event_id, 0) &amp;gt; mvindex(event_id, -1)
  OR mvindex(_time, 0) &amp;lt; mvindex(_time, -1) AND mvindex(event_id, 0) &amp;lt; mvindex(event_id, -1)
| fieldformat _time = strftime(_time, "%F %H:%M:%S.%3Q")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is an emulation of your sample data that you can play with and compare with real data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval data = split("8/01/2023 3:52:40.395 PM  server_state|3 1223681 5
8/01/2023 3:50:40.395 PM  server_state|2 1201257 3
8/01/2023 3:45:40.395 PM  server_state|1 1135465 2
8/01/2023 3:41:40.395 PM  server_state|0 1545468 5
8/01/2023 3:36:40.395 PM  server_state|3 1223680 0
8/01/2023 3:25:40.395 PM  server_state|2 1201256 2
8/01/2023 3:15:40.395 PM  server_state|1 1135464 3
8/01/2023 3:10:40.395 PM  server_state|0 1545467 8", "
")
| mvexpand data
| rename data as _raw
| rex "(?&amp;lt;ts&amp;gt;(\S+\s){3}) (?&amp;lt;event_name&amp;gt;\w+)\|(?&amp;lt;task_id&amp;gt;\d+) (?&amp;lt;event_id&amp;gt;\d+)"
| eval _time = strptime(ts, "%m/%d/%Y %I:%M:%S.%3Q %p")
``` data emulation above ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 06:04:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656194#M226644</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-08-31T06:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656341#M226697</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the reply.&amp;nbsp; The table view is great. What I was trying to achieve is that to trigger an alert, for example, from the below table, if the latest event_id is "1545467"&amp;nbsp; compared to last/previous event_id (which is also 1545467) for the same task_id, event_name for last 2 hours, then alert should be triggered. Since there is no change in the event_id, it should trigger an alert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;event_name&lt;/TD&gt;&lt;TD&gt;task_id&lt;/TD&gt;&lt;TD&gt;_time&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;event_id&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;server_state&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;2023-08-01 15:41:40.395,2023-08-01 15:10:40.395&lt;/TD&gt;&lt;TD&gt;&lt;DIV class=""&gt;1545467&lt;/DIV&gt;&lt;DIV class=""&gt;1545467&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 31 Aug 2023 21:52:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656341#M226697</guid>
      <dc:creator>pukka</dc:creator>
      <dc:date>2023-08-31T21:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656344#M226698</link>
      <description>&lt;P&gt;Your original post says "&lt;SPAN&gt;create an alert&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;if there is an increment." &amp;nbsp;If you want to alert when there is &lt;U&gt;no change&lt;/U&gt;, i.e., no increment or decrement, the formula would be simpler because we don't have calculate whether a change is an increment or decrement.&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats list(_time) as _time list(event_id) as event_id by event_name task_id
| where mvindex(event_id, 0) = mvindex(event_id, -1)
| fieldformat _time = strftime(_time, "%F %H:%M:%S.%3Q")&lt;/LI-CODE&gt;&lt;P&gt;This is a modified emulation where task_id 0 has no change in event_id&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval data = split("8/01/2023 3:52:40.395 PM  server_state|3 1223681 5
8/01/2023 3:50:40.395 PM  server_state|2 1201257 3
8/01/2023 3:45:40.395 PM  server_state|1 1135465 2
8/01/2023 3:41:40.395 PM  server_state|0 1545467 5
8/01/2023 3:36:40.395 PM  server_state|3 1223680 0
8/01/2023 3:25:40.395 PM  server_state|2 1201256 2
8/01/2023 3:15:40.395 PM  server_state|1 1135464 3
8/01/2023 3:10:40.395 PM  server_state|0 1545467 8", "
")
| mvexpand data
| rename data as _raw
| rex "(?&amp;lt;ts&amp;gt;(\S+\s){3}) (?&amp;lt;event_name&amp;gt;\w+)\|(?&amp;lt;task_id&amp;gt;\d+) (?&amp;lt;event_id&amp;gt;\d+)"
| eval _time = strptime(ts, "%m/%d/%Y %I:%M:%S.%3Q %p")
``` data emulation above ```&lt;/LI-CODE&gt;&lt;P&gt;This gives you the exact output you ask.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2023 22:15:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656344#M226698</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-08-31T22:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656476#M226743</link>
      <description>&lt;P&gt;I apologize for the confusion.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found out that the splunk field extraction feature failed to extract the fields becuase of two different delimiter pipe and space. Looks I need to change&amp;nbsp; log format to all pipes or spaces so that splun would be able to extract the fields correctly.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 21:22:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656476#M226743</guid>
      <dc:creator>pukka</dc:creator>
      <dc:date>2023-09-01T21:22:14Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656485#M226744</link>
      <description>&lt;P&gt;I am not sure why Splunk cannot handle spaces and pipe as delimiter. &amp;nbsp;Have you tried the rex command in my emulation?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| rex "(?&amp;lt;ts&amp;gt;(\S+\s){3}) (?&amp;lt;event_name&amp;gt;\w+)\|(?&amp;lt;task_id&amp;gt;\d+) (?&amp;lt;event_id&amp;gt;\d+)"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;In your case, you probably do not need ts extraction because Splunk already gives you _time.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Sep 2023 00:30:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656485#M226744</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-09-02T00:30:20Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656720#M226818</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The reason splunk is unable to extract the fields using in-built filed extraction becuase it only allows to extract either pipe, comma, space but not if the event contains multiple delimiters like pipe, space.&lt;/P&gt;&lt;P&gt;Thank You for sharing the rex command. I have tried the rex command however, I have changed the log format to include additional details. I have&amp;nbsp; played with regex that you shared by making changes but however, it&amp;nbsp; extract only the portion of event_name. I believe it is mainly because of the new format that has a long event_name compared to previous log forma. For example,&amp;nbsp; &lt;STRONG&gt;&lt;EM&gt;abc-pendingcardtransfer-networki &lt;/EM&gt;&lt;/STRONG&gt;it only extracts "abc" as event name and I am trying to update the regex to exclude event&amp;nbsp; that starts with &lt;EM&gt;[INFO]&amp;nbsp;&amp;nbsp;&lt;/EM&gt;as it is not required.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(?&amp;lt;event_name&amp;gt;\w+)\|(?&amp;lt;task_id&amp;gt;\d+) (?&amp;lt;event_id&amp;gt;\d+)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New sample log format:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;abc-pendingcardtransfer-networki|30 77784791 1547
logs-incomingtransaction-datainpu|3 7876821 1458
[INFO] 2019-09-01 13:52:38.22 [main] Apache - Number of netwrok events is 25
dog-acceptedtransactions-incoming|1 746566 1887
sfgd_SGDJELE|2 0 0
es009874_e026516516|28 455255555 785&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 19:43:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656720#M226818</guid>
      <dc:creator>pukka</dc:creator>
      <dc:date>2023-09-05T19:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656753#M226830</link>
      <description>&lt;P&gt;You can use&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;\b(?&amp;lt;event_name&amp;gt;[^|]+)\|(?&amp;lt;task_id&amp;gt;\d+) (?&amp;lt;event_id&amp;gt;\d+)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You know you don't have to use delimiter to extract fields. &amp;nbsp;You can select regex instead. &amp;nbsp;This is one way to do it:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="extract-prefer-regex.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27069iD7C1EA4D908E0B88/image-size/medium?v=v2&amp;amp;px=400" role="button" title="extract-prefer-regex.png" alt="extract-prefer-regex.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="extract-regex.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27070iFBF60CB9E880465C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="extract-regex.png" alt="extract-regex.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Alternatively, you can use the selector. (Most of the time, Splunk will come up with a good regex.)&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 04:44:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/656753#M226830</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-09-06T04:44:33Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657023#M226941</link>
      <description>&lt;P&gt;Thank you for the help. I was able to extract the fields now.&lt;/P&gt;&lt;P&gt;When I run the query 1, I have found that event_name "pending-transfer" with a task_id of 3 have event_id "1274856" being repeated three times in a row which means that there is no increment in the event_id. However, when I run the query 2 for the same event_name " pending-transfer", it doesn't give any output. Technically, query 2 should send an alert ( I have created the alert to run at every minute but still NO alert was triggered ) because there is no change in the &lt;U&gt;&lt;STRONG&gt;event_id&lt;/STRONG&gt;&lt;/U&gt; for the event that was triggered at &lt;FONT color="#FF0000"&gt;9/4/22 10:02:39 PM&lt;/FONT&gt; and &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;9/4/22 09:57:39 PM&amp;nbsp;&lt;/STRONG&gt; &lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Not sure if I am missing something.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Query 1 : Alert if there is an increment&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats list(_time) as _time list(event_id) as event_id by event_name task_id
| where mvindex(_time, 0) &amp;gt; mvindex(_time, -1) AND mvindex(event_id, 0) &amp;gt; mvindex(event_id, -1)
  OR mvindex(_time, 0) &amp;lt; mvindex(_time, -1) AND mvindex(event_id, 0) &amp;lt; mvindex(event_id, -1)
| fieldformat _time = strftime(_time, "%F %H:%M:%S.%3Q")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the output that I am getting when I run the &lt;STRONG&gt;query 1&lt;/STRONG&gt;:&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%" height="24px"&gt;&lt;STRONG&gt;Time&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;STRONG&gt;event_name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;STRONG&gt;task_id&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;STRONG&gt;event_id&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#0000FF"&gt;9/4/22 10:02:39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#0000FF"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#0000FF"&gt;3&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#0000FF"&gt;1274856&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;&lt;FONT color="#0000FF"&gt;9/4/22 09:57:39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#0000FF"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#0000FF"&gt;3&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#0000FF"&gt;1274856&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;&lt;FONT color="#0000FF"&gt;9/4/22 09:52:39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#0000FF"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#0000FF"&gt;3&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#0000FF"&gt;1274856&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;9/4/22 09:47:39 PM&lt;/TD&gt;&lt;TD width="25%"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="25%"&gt;3&lt;/TD&gt;&lt;TD width="25%"&gt;1274851&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;9/4/22 09:37:39 PM&lt;/TD&gt;&lt;TD width="25%"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="25%"&gt;3&lt;/TD&gt;&lt;TD width="25%"&gt;1274849&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Query 2 : Alert if there is NO increment&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats list(_time) as _time list(event_id) as event_id by event_name task_id
| where mvindex(event_id, 0) = mvindex(event_id, -1)
| fieldformat _time = strftime(_time, "%F %H:%M:%S.%3Q")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 06:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657023#M226941</guid>
      <dc:creator>pukka</dc:creator>
      <dc:date>2023-09-08T06:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657028#M226943</link>
      <description>&lt;P&gt;Ah, the original design did not consider the possibility of mixed increment and no-increment. &amp;nbsp;Now, to deal with this, you will need to tell us whether you want to catch any duplicate regardless of interleave, or whether you want to catch only "consecutive" events that duplicate event_id, because the two use cases are very different.&lt;/P&gt;&lt;P&gt;If only consecutive duplicate event_id should trigger alert, you can do&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| delta event_id as delta
| stats list(_time) as _time values(delta) as delta by event_id event_name task_id
| where delta == "0"
| fieldformat _time = strftime(_time, "%F %H:%M:%S.%3Q")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To test this use case, I construct the following extended test dataset based on your illustration.&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Time&lt;/TD&gt;&lt;TD&gt;_time&lt;/TD&gt;&lt;TD&gt;event_id&lt;/TD&gt;&lt;TD&gt;event_name&lt;/TD&gt;&lt;TD&gt;task_id&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/4/22 10:03:39 PM&lt;/TD&gt;&lt;TD&gt;2022-09-04 22:03:39&lt;/TD&gt;&lt;TD&gt;1274851&lt;/TD&gt;&lt;TD&gt;pending-transfer&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/4/22 10:02:39 PM&lt;/TD&gt;&lt;TD&gt;2022-09-04 22:02:39&lt;/TD&gt;&lt;TD&gt;1274856&lt;/TD&gt;&lt;TD&gt;pending-transfer&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/4/22 09:57:39 PM&lt;/TD&gt;&lt;TD&gt;2022-09-04 21:57:39&lt;/TD&gt;&lt;TD&gt;1274856&lt;/TD&gt;&lt;TD&gt;pending-transfer&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/4/22 09:52:39 PM&lt;/TD&gt;&lt;TD&gt;2022-09-04 21:52:39&lt;/TD&gt;&lt;TD&gt;1274856&lt;/TD&gt;&lt;TD&gt;pending-transfer&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/4/22 09:47:39 PM&lt;/TD&gt;&lt;TD&gt;2022-09-04 21:47:39&lt;/TD&gt;&lt;TD&gt;1274851&lt;/TD&gt;&lt;TD&gt;pending-transfer&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;9/4/22 09:37:39 PM&lt;/TD&gt;&lt;TD&gt;2022-09-04 21:37:39&lt;/TD&gt;&lt;TD&gt;1274849&lt;/TD&gt;&lt;TD&gt;pending-transfer&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;And the result is a single row&lt;/P&gt;&lt;TABLE width="791px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="78.203125px"&gt;event_id&lt;/TD&gt;&lt;TD width="113.96875px"&gt;event_name&lt;/TD&gt;&lt;TD width="64px"&gt;task_id&lt;/TD&gt;&lt;TD width="485.859375px"&gt;_time&lt;/TD&gt;&lt;TD width="48px"&gt;&lt;DIV class=""&gt;delta&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="78.203125px"&gt;1274856&lt;/TD&gt;&lt;TD width="113.96875px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="64px"&gt;3&lt;/TD&gt;&lt;TD width="485.859375px"&gt;2022-09-04 22:02:39.000,2022-09-04 21:57:39.000,2022-09-04 21:52:39.000&lt;/TD&gt;&lt;TD width="48px"&gt;&lt;DIV class=""&gt;0&lt;/DIV&gt;&lt;DIV class=""&gt;5&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;If, on the other hand, the alert should be triggered no matter which other event_id's are in between, you should do&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats list(_time) as _time by event_id event_name task_id
| where mvcount(_time) &amp;gt; 1
| fieldformat _time = strftime(_time, "%F %H:%M:%S.%3Q")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using the same test dataset as illustrated above, you should see two outputs&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;event_id&lt;/TD&gt;&lt;TD&gt;event_name&lt;/TD&gt;&lt;TD&gt;task_id&lt;/TD&gt;&lt;TD&gt;_time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1274851&lt;/TD&gt;&lt;TD&gt;pending-transfer&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;2022-09-04 22:03:39.000,2022-09-04 21:47:39.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1274856&lt;/TD&gt;&lt;TD&gt;pending-transfer&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;2022-09-04 22:02:39.000,2022-09-04 21:57:39.000,2022-09-04 21:52:39.000&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Here is data emulation that you can play with and compare with real data&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw = "Time	event_name	task_id	event_id
9/4/22 10:03:39 PM	pending-transfer	3	1274851
9/4/22 10:02:39 PM	pending-transfer	3	1274856
9/4/22 09:57:39 PM	pending-transfer	3	1274856
9/4/22 09:52:39 PM	pending-transfer	3	1274856
9/4/22 09:47:39 PM	pending-transfer	3	1274851
9/4/22 09:37:39 PM	pending-transfer	3	1274849"
| multikv
| eval _time = strptime(Time, "%m/%d/%y %I:%M:%S %p")
| fields - linecount _raw
``` data emulation above ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2023 08:28:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657028#M226943</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-09-08T08:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657386#M227067</link>
      <description>&lt;P&gt;I apologize for the confusion. I will try my best to explain it better.&lt;/P&gt;&lt;P&gt;For example,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Event_name = pending-transfer&lt;/P&gt;&lt;P&gt;number of task_id's that event_name (pending-transfer) has "3"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below table contains the&amp;nbsp;&lt;STRONG&gt; event_id's &lt;/STRONG&gt;recieved by the "pending-transfer" for different&lt;STRONG&gt; task_id's &lt;/STRONG&gt;at &lt;STRONG&gt;9:30 PM&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Table 1&lt;/EM&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%" height="24px"&gt;&lt;STRONG&gt;Time&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;STRONG&gt;event_name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;STRONG&gt;task_id&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;STRONG&gt;event_id&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;9/4/22 &lt;FONT color="#FF0000"&gt;09:40&lt;/FONT&gt;:39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;1&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;1274856&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;9/4/22 &lt;FONT color="#FF0000"&gt;09:35:&lt;/FONT&gt;39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;2&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;1274856&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;9/4/22 &lt;FONT color="#FF0000"&gt;09:30&lt;/FONT&gt;:39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;3&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%"&gt;&lt;FONT color="#000000"&gt;1274817&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At &lt;STRONG&gt;10:00 PM&lt;/STRONG&gt;, there are new&lt;STRONG&gt; event_id's&lt;/STRONG&gt; for different &lt;STRONG&gt;task_id's&lt;/STRONG&gt; for "pending-transfer" as shown below.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Table 2&lt;/EM&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="25%" height="25px"&gt;&lt;STRONG&gt;Time&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&lt;STRONG&gt;event_name&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&lt;STRONG&gt;task_id&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="25%" height="25px"&gt;&lt;STRONG&gt;event_id&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;9/4/22 &lt;FONT color="#FF0000"&gt;10:10&lt;/FONT&gt;:39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;1&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#00FF00"&gt;1274856&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;9/4/22 &lt;FONT color="#FF0000"&gt;10:05:&lt;/FONT&gt;39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;2&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;1274748&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;9/4/22 &lt;FONT color="#FF0000"&gt;10:00&lt;/FONT&gt;:39 PM&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;pending-transfer&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;3&lt;/FONT&gt;&lt;/TD&gt;&lt;TD width="25%" height="24px"&gt;&lt;FONT color="#000000"&gt;1274902&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For task_id = 1 , there is no change in the event_id (&lt;U&gt;1274856&lt;/U&gt;) for event_id arrived at &lt;STRONG&gt;10:10 PM&lt;/STRONG&gt; compared to the previous event_id at &lt;STRONG&gt;9:40 PM&lt;/STRONG&gt; whereas for other task_id's (task_id=2, task_id=3) there is a change in the event_id.&amp;nbsp; Therefore, alert needs to be generated since there is no change in event_id for task_id=1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, logic needs to check if there is a change in event_id for &lt;STRONG&gt;ALL&lt;/STRONG&gt; task_id's in an event_name and if there is NO change in event_id for &lt;STRONG&gt;ANY&lt;/STRONG&gt; of task_id's in an event_name, then&amp;nbsp; alert needs to be triggered.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will be creating the alert for each event_name by using where clause.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splun query | where event_name = "pending-transfer"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I am not planning to create alert for each specific task_id in the event_name as it lead to so many alerts.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk query | where event_name = "pending-transfer" task_id=1
splunk query | where event_name = "pending-transfer" task_id=2
splunk query | where event_name = "pending-transfer" task_id=3&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 05:53:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657386#M227067</guid>
      <dc:creator>pukka</dc:creator>
      <dc:date>2023-09-13T05:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657399#M227072</link>
      <description>&lt;P&gt;Each time you are making very different statements of the requirements. &amp;nbsp;I am not sure it is worth my time to propose search until you can define your requirements in terms of data examples. (Use cases.)&lt;/P&gt;&lt;P&gt;So, let me clarify one more time with data. &amp;nbsp;This first set has two task_id's (out of three) that changed event_id (let's forget about increment or decrement for now) during the time period. &amp;nbsp;There fore this set should not alarm:&lt;/P&gt;&lt;TABLE width="423px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;_time&lt;/TD&gt;&lt;TD width="78.203125px"&gt;eventg_id&lt;/TD&gt;&lt;TD width="131.5625px"&gt;event_name&lt;/TD&gt;&lt;TD width="46.953125px"&gt;task_id&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;2022-09-04 21:40:39&lt;/TD&gt;&lt;TD width="78.203125px"&gt;1274856&lt;/TD&gt;&lt;TD width="131.5625px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="46.953125px"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;2022-09-04 21:35:39&lt;/TD&gt;&lt;TD width="78.203125px"&gt;1274856&lt;/TD&gt;&lt;TD width="131.5625px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="46.953125px"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;2022-09-04 21:30:39&lt;/TD&gt;&lt;TD width="78.203125px"&gt;1274817&lt;/TD&gt;&lt;TD width="131.5625px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="46.953125px"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;2022-09-04 22:10:39&lt;/TD&gt;&lt;TD width="78.203125px"&gt;1274856&lt;/TD&gt;&lt;TD width="131.5625px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="46.953125px"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;2022-09-04 22:05:39&lt;/TD&gt;&lt;TD width="78.203125px"&gt;1274748&lt;/TD&gt;&lt;TD width="131.5625px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="46.953125px"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;2022-09-04 22:00:39&lt;/TD&gt;&lt;TD width="78.203125px"&gt;1274902&lt;/TD&gt;&lt;TD width="131.5625px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="46.953125px"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Let me construct a slightly different set in which every event_id has a unchanging task_id&lt;/P&gt;&lt;TABLE width="423px"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;_time&lt;/TD&gt;&lt;TD width="78.203125px"&gt;event_id&lt;/TD&gt;&lt;TD width="131.5625px"&gt;event_name&lt;/TD&gt;&lt;TD width="46.953125px"&gt;task_id&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;2022-09-04 21:40:39&lt;/TD&gt;&lt;TD width="78.203125px"&gt;1274856&lt;/TD&gt;&lt;TD width="131.5625px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="46.953125px"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;2022-09-04 21:35:39&lt;/TD&gt;&lt;TD width="78.203125px"&gt;1274748&lt;/TD&gt;&lt;TD width="131.5625px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="46.953125px"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;2022-09-04 21:30:39&lt;/TD&gt;&lt;TD width="78.203125px"&gt;1274902&lt;/TD&gt;&lt;TD width="131.5625px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="46.953125px"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;2022-09-04 22:10:39&lt;/TD&gt;&lt;TD width="78.203125px"&gt;1274856&lt;/TD&gt;&lt;TD width="131.5625px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="46.953125px"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;2022-09-04 22:05:39&lt;/TD&gt;&lt;TD width="78.203125px"&gt;1274748&lt;/TD&gt;&lt;TD width="131.5625px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="46.953125px"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="165.296875px"&gt;2022-09-04 22:00:39&lt;/TD&gt;&lt;TD width="78.203125px"&gt;1274902&lt;/TD&gt;&lt;TD width="131.5625px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="46.953125px"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;With the second set, you want an alert.&lt;/P&gt;&lt;P&gt;Do the above sufficiently capture use case requirements? &amp;nbsp;Here are emulations of the two sets&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw = "Time	event_name	task_id	event_id
9/4/22 09:40:39 PM	pending-transfer	1	1274856
9/4/22 09:35:39 PM	pending-transfer	2	1274856
9/4/22 09:30:39 PM	pending-transfer	3	1274817
9/4/22 10:10:39 PM	pending-transfer	1	1274856
9/4/22 10:05:39 PM	pending-transfer	2	1274748
9/4/22 10:00:39 PM	pending-transfer	3	1274902"
| multikv
| eval _time = strptime(Time, "%m/%d/%y %I:%M:%S %p")
| fields - linecount _raw
``` data emulation set 1 ```&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;| makeresults
| eval _raw = "Time	event_name	task_id	event_id
9/4/22 10:10:39 PM	pending-transfer	1	1274856
9/4/22 10:05:39 PM	pending-transfer	2	1274748
9/4/22 10:00:39 PM	pending-transfer	3	1274902
9/4/22 09:40:39 PM	pending-transfer	1	1274856
9/4/22 09:35:39 PM	pending-transfer	2	1274748
9/4/22 09:30:39 PM	pending-transfer	3	1274902"
| multikv
| eval _time = strptime(Time, "%m/%d/%y %I:%M:%S %p")
| fields - linecount _raw
``` data emulation set 2 ```&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there are additional cases to be differentiated, please play with the emulations and construct differentiation.&lt;/P&gt;&lt;P&gt;Again, forget how many alerts you want to send. &amp;nbsp;Just focus on data input and whether or not a given dataset should trigger alert.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 08:00:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657399#M227072</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-09-13T08:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657530#M227118</link>
      <description>&lt;P&gt;hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate all your responses and I hope the below flowchart makes the requirement clear.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="flowchart_2.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27173i711DC1E351189E51/image-size/large?v=v2&amp;amp;px=999" role="button" title="flowchart_2.png" alt="flowchart_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 05:26:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657530#M227118</guid>
      <dc:creator>pukka</dc:creator>
      <dc:date>2023-09-14T05:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657782#M227183</link>
      <description>&lt;P&gt;HI &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/33901"&gt;@yuanliu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Please note that task_id's for event_name are constant and only event_id's going to change. Moreover, even if one task_id have an unchanged event_id, then it should trigger an alert.&amp;nbsp; The alert should be triggered only if there is unchanged event_id for the corresponding task_id. To your question, the alert should be triggered with both set-1 and set-2 because set-1 have one unchanged event_id whereas set-2 have three unchanged event_id's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 22:23:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657782#M227183</guid>
      <dc:creator>pukka</dc:creator>
      <dc:date>2023-09-15T22:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Tempory output storage</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657846#M227225</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;question, the alert should be triggered with both set-1 and set-2 because set-1 have one unchanged event_id whereas set-2 have three unchanged event_id's.&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;In that case,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats list(_time) as _time by event_id event_name task_id
| where mvcount(_time) &amp;gt; 1
| fieldformat _time = strftime(_time, "%F %H:%M:%S.%3Q")&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;should suffice. &amp;nbsp;The emulated dataset 1 gives&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="78.203125px" height="25px"&gt;event_id&lt;/TD&gt;&lt;TD width="132.046875px" height="25px"&gt;event_name&lt;/TD&gt;&lt;TD width="63.9375px" height="25px"&gt;task_id&lt;/TD&gt;&lt;TD width="388px" height="25px"&gt;_time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="78.203125px" height="25px"&gt;1274856&lt;/TD&gt;&lt;TD width="132.046875px" height="25px"&gt;pending-transfer&lt;/TD&gt;&lt;TD width="63.9375px" height="25px"&gt;1&lt;/TD&gt;&lt;TD width="388px" height="25px"&gt;2022-09-04 21:40:39.000,2022-09-04 22:10:39.000&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Emulated dataset 2 gives&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;event_id&lt;/TD&gt;&lt;TD&gt;event_name&lt;/TD&gt;&lt;TD&gt;task_id&lt;/TD&gt;&lt;TD&gt;_time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1274748&lt;/TD&gt;&lt;TD&gt;pending-transfer&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;2022-09-04 22:05:39.000,2022-09-04 21:35:39.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1274856&lt;/TD&gt;&lt;TD&gt;pending-transfer&lt;/TD&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;2022-09-04 22:10:39.000,2022-09-04 21:40:39.000&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1274902&lt;/TD&gt;&lt;TD&gt;pending-transfer&lt;/TD&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;2022-09-04 22:00:39.000,2022-09-04 21:30:39.000&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Can you show a dataset that the above does not meet the requirement? (Just modify the emulations so we are on the same page.)&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 06:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Tempory-output-storage/m-p/657846#M227225</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-09-18T06:29:29Z</dc:date>
    </item>
  </channel>
</rss>

