<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Classify into a group in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Classify-into-a-group/m-p/668282#M229256</link>
    <description>&lt;LI-CODE lang="markup"&gt;| rex field=logs "\|(?&amp;lt;msg&amp;gt;.+)$"
| stats sum(eval(case(msg=="**Starting**",1,msg=="Shutting down",-1))) as bad count(eval(case(msg=="**Starting**",1))) as starts
| eval good=starts-bad&lt;/LI-CODE&gt;</description>
    <pubDate>Fri, 10 Nov 2023 21:54:54 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2023-11-10T21:54:54Z</dc:date>
    <item>
      <title>Classify into a group</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Classify-into-a-group/m-p/668273#M229253</link>
      <description>&lt;P&gt;Example logs&lt;/P&gt;&lt;P&gt;2022-08-19 08:10:53.0593|**Starting**&lt;/P&gt;&lt;P&gt;2022-08-19 08:10:53.5905|fff&lt;/P&gt;&lt;P&gt;2022-08-19 08:10:53.6061|dd&lt;/P&gt;&lt;P&gt;2022-08-19 08:10:53.6218|Shutting down&lt;/P&gt;&lt;P&gt;2022-08-19 08:10:53.6218|**Starting**&lt;/P&gt;&lt;P&gt;2022-08-19 08:10:53.6374|fffff&lt;/P&gt;&lt;P&gt;2022-08-19 08:10:53.6686|ddd&lt;/P&gt;&lt;P&gt;2022-08-19 08:10:53.6843|**Starting**&lt;/P&gt;&lt;P&gt;2022-08-19 08:10:54.1530|aa&lt;/P&gt;&lt;P&gt;2022-08-19 08:10:54.1530|vv&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From this I have created three columns Devicenumber, &amp;nbsp;_time ,Description&lt;/P&gt;&lt;P&gt;If ** Starting ** message has followed by "Shutting down" mean, it should classify as good and if Starting message has not Shutting down mean, it should classify as bad.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the above example, there should be 2 bad and one good.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there is only one row which has only Starting and no shutting down recorded, in that case also , it should classify as bad&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 18:46:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Classify-into-a-group/m-p/668273#M229253</guid>
      <dc:creator>Kirthika</dc:creator>
      <dc:date>2023-11-10T18:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: Classify into a group</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Classify-into-a-group/m-p/668282#M229256</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex field=logs "\|(?&amp;lt;msg&amp;gt;.+)$"
| stats sum(eval(case(msg=="**Starting**",1,msg=="Shutting down",-1))) as bad count(eval(case(msg=="**Starting**",1))) as starts
| eval good=starts-bad&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 10 Nov 2023 21:54:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Classify-into-a-group/m-p/668282#M229256</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-10T21:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Classify into a group</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Classify-into-a-group/m-p/668339#M229281</link>
      <description>&lt;P&gt;Nice SPL&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;..&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254923"&gt;@Kirthika&lt;/a&gt;&amp;nbsp;.. pls check this SPL.. (the stats logic may needs to be fine-tuned)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;source="testlogrex.txt" host="laptop" sourcetype="nov12"
| rex field=_raw "\|(?&amp;lt;msg&amp;gt;.+)$"
| stats sum(eval(case(msg=="**Starting**",1,msg=="Shutting down",-1))) as bad count(eval(case(msg=="**Starting**",1))) as starts
| eval good=starts-bad&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this SPL gives this result..&amp;nbsp;&lt;/P&gt;&lt;P&gt;bad starts good&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;TD&gt;7&lt;/TD&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;The Sample logs and rex used here:&lt;/P&gt;&lt;P&gt;source="testlogrex.txt" host="laptop" sourcetype="nov12"&lt;BR /&gt;| rex field=_raw "\|(?&amp;lt;msg&amp;gt;.+)$"&lt;BR /&gt;| table _raw msg&lt;/P&gt;&lt;P&gt;_raw msg&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:04.6218|Shutting down&lt;/TD&gt;&lt;TD&gt;Shutting down&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:03.6061|dd03&lt;/TD&gt;&lt;TD&gt;dd03&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:02.5905|fff&lt;/TD&gt;&lt;TD&gt;fff&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:01.0593|**Starting**&lt;/TD&gt;&lt;TD&gt;**Starting**&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:08.6843|**Starting**&lt;/TD&gt;&lt;TD&gt;**Starting**&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:07.6686|ddd07&lt;/TD&gt;&lt;TD&gt;ddd07&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:06.6374|fffff06&lt;/TD&gt;&lt;TD&gt;fffff06&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:05.6218|**Starting**&lt;/TD&gt;&lt;TD&gt;**Starting**&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:12.5905|fff12&lt;/TD&gt;&lt;TD&gt;fff12&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:11.0593|**Starting**&lt;/TD&gt;&lt;TD&gt;**Starting**&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:10.1530|vv10&lt;/TD&gt;&lt;TD&gt;vv10&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:09.1530|aa09&lt;/TD&gt;&lt;TD&gt;aa09&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:16.6374|fffff16&lt;/TD&gt;&lt;TD&gt;fffff16&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:15.6218|**Starting**&lt;/TD&gt;&lt;TD&gt;**Starting**&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:14.6218|Shutting down&lt;/TD&gt;&lt;TD&gt;Shutting down&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:13.6061|**Starting**&lt;/TD&gt;&lt;TD&gt;**Starting**&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:19.15|aa19&lt;/TD&gt;&lt;TD&gt;aa19&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:18.6843|**Starting**&lt;/TD&gt;&lt;TD&gt;**Starting**&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:17.6686|ddd17&lt;/TD&gt;&lt;TD&gt;ddd17&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2022-08-19 08:10:20.160|vv20&lt;/TD&gt;&lt;TD&gt;vv20&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Sun, 12 Nov 2023 05:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Classify-into-a-group/m-p/668339#M229281</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2023-11-12T05:20:32Z</dc:date>
    </item>
  </channel>
</rss>

