<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Missing settlement notification in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Missing-settlement-notification/m-p/658721#M227517</link>
    <description>&lt;P&gt;Please edit your query to use code blocks&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bowesmana_0-1695714501872.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27329i2D767A3AA21BC37F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bowesmana_0-1695714501872.png" alt="bowesmana_0-1695714501872.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/&amp;gt; to format it - as it stands is almost impossible to work out what is your query - plenty of strange things in there, including a random &lt;STRONG&gt;K&lt;/STRONG&gt; and a &lt;STRONG&gt;plus sign&lt;/STRONG&gt; and seemingly missing &lt;STRONG&gt;pipe&lt;/STRONG&gt; symbols as well as missing double quotes where they would be expected and stats clauses that don't make a lot of sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Sep 2023 07:50:47 GMT</pubDate>
    <dc:creator>bowesmana</dc:creator>
    <dc:date>2023-09-26T07:50:47Z</dc:date>
    <item>
      <title>Missing settlement notification</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Missing-settlement-notification/m-p/658707#M227515</link>
      <description>&lt;P&gt;Event and Report extract rules&lt;/P&gt;&lt;P&gt;Use the payment business events to identify Transactions which have ACCP clearing status (NPP 1012.NPP 1013) with missing Settlement Notification event NPP 1040&lt;/P&gt;&lt;P&gt;"NPP 1033_CR_INBOUND "NPP 1012 CECARING_INBOUND"&lt;/P&gt;&lt;P&gt;• "NPP 1013_RETURN_INBOUND" I&lt;/P&gt;&lt;P&gt;"NPP 1040 SETTLEMENT RECEIVED" Report should include the following fields&lt;/P&gt;&lt;P&gt;Time from NPP 1033&lt;/P&gt;&lt;P&gt;TXID from NPP 1033 Amount from NPP 1012 or NPP 1013&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Already i have created query&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index-nch_apps_nonprod applications fis-npp source fis-npp-sit4 ((NPP 1012 CLEARING INBOUND OR NPP 1013 RETURN INBOUND) OR NPP 1033 CR INBOUND or&lt;/P&gt;&lt;P&gt;rex field-message "eventName=\"(?&amp;lt;eventName&amp;gt; *?)\"."&lt;/P&gt;&lt;P&gt;rex field-message "txId\"(?&amp;lt;txId&amp;gt;. *?)\,"&lt;/P&gt;&lt;P&gt;Κ&lt;/P&gt;&lt;P&gt;I rex field-message "amt=\"(?&amp;lt;amt&amp;gt;.2)\"." rex field-message ibm.datetime-(?&amp;lt;ibm_datetime&amp;gt; *),"&lt;/P&gt;&lt;P&gt;+&lt;/P&gt;&lt;P&gt;Participant&lt;/P&gt;&lt;P&gt;1 eval Participant substr(txId,1,8)&lt;/P&gt;&lt;P&gt;stats values(eventName) as eventName, min(ibt datetime) as Time, values(amt) as amt by (eventName, NPP 1840 SETTLEMENT RECEIVED) &amp;lt; 0 table Time eventName Participant amt&lt;/P&gt;&lt;P&gt;where mycount (eventName)&lt;/P&gt;&lt;P&gt;&amp;gt;= 3 AND mvfind (eventName, npp 1040) but not getting any result&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 04:41:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Missing-settlement-notification/m-p/658707#M227515</guid>
      <dc:creator>Sekhar</dc:creator>
      <dc:date>2023-09-26T04:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Missing settlement notification</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Missing-settlement-notification/m-p/658721#M227517</link>
      <description>&lt;P&gt;Please edit your query to use code blocks&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bowesmana_0-1695714501872.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/27329i2D767A3AA21BC37F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bowesmana_0-1695714501872.png" alt="bowesmana_0-1695714501872.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/&amp;gt; to format it - as it stands is almost impossible to work out what is your query - plenty of strange things in there, including a random &lt;STRONG&gt;K&lt;/STRONG&gt; and a &lt;STRONG&gt;plus sign&lt;/STRONG&gt; and seemingly missing &lt;STRONG&gt;pipe&lt;/STRONG&gt; symbols as well as missing double quotes where they would be expected and stats clauses that don't make a lot of sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Sep 2023 07:50:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Missing-settlement-notification/m-p/658721#M227517</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-09-26T07:50:47Z</dc:date>
    </item>
  </channel>
</rss>

