<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Search log for alert in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-log-for-alert/m-p/336706#M99899</link>
    <description>&lt;P&gt;Have good day for Everybody&lt;BR /&gt;
Pls help me to search exactly the content.&lt;BR /&gt;
My input log is: &lt;BR /&gt;
status system replication site "1": ERROR&lt;BR /&gt;
status system replication site "3": ACTIVE&lt;BR /&gt;
overall system replication status: ERROR.&lt;BR /&gt;
My search and will add the alert: &lt;BR /&gt;
index="...." host="..." status system replication site "1": ACTIVE | head 1&lt;BR /&gt;
the result is:&lt;BR /&gt;
&lt;STRONG&gt;status system replication site "1"&lt;/STRONG&gt;: ERROR&lt;BR /&gt;
status system replication site "3": &lt;STRONG&gt;ACTIVE&lt;/STRONG&gt;&lt;BR /&gt;
overall system replication status: ERROR.&lt;BR /&gt;
But i couldn't know: site "1" ACTIVE or ERROR.&lt;BR /&gt;
Pls help me define the searching.&lt;BR /&gt;
Thank &lt;/P&gt;</description>
    <pubDate>Tue, 12 Dec 2017 02:51:01 GMT</pubDate>
    <dc:creator>dangtran</dc:creator>
    <dc:date>2017-12-12T02:51:01Z</dc:date>
    <item>
      <title>Search log for alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-log-for-alert/m-p/336706#M99899</link>
      <description>&lt;P&gt;Have good day for Everybody&lt;BR /&gt;
Pls help me to search exactly the content.&lt;BR /&gt;
My input log is: &lt;BR /&gt;
status system replication site "1": ERROR&lt;BR /&gt;
status system replication site "3": ACTIVE&lt;BR /&gt;
overall system replication status: ERROR.&lt;BR /&gt;
My search and will add the alert: &lt;BR /&gt;
index="...." host="..." status system replication site "1": ACTIVE | head 1&lt;BR /&gt;
the result is:&lt;BR /&gt;
&lt;STRONG&gt;status system replication site "1"&lt;/STRONG&gt;: ERROR&lt;BR /&gt;
status system replication site "3": &lt;STRONG&gt;ACTIVE&lt;/STRONG&gt;&lt;BR /&gt;
overall system replication status: ERROR.&lt;BR /&gt;
But i couldn't know: site "1" ACTIVE or ERROR.&lt;BR /&gt;
Pls help me define the searching.&lt;BR /&gt;
Thank &lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 02:51:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-log-for-alert/m-p/336706#M99899</guid>
      <dc:creator>dangtran</dc:creator>
      <dc:date>2017-12-12T02:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Search log for alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-log-for-alert/m-p/336707#M99900</link>
      <description>&lt;P&gt;Hi dangtran,&lt;BR /&gt;
let me understand: do you want to find the first occurrance of the string &lt;CODE&gt;status system replication site "1": ACTIVE&lt;/CODE&gt; or other?&lt;BR /&gt;
If you want the exact string use quotes (").&lt;/P&gt;

&lt;P&gt;There's a thing that I don't understand: you used &lt;CODE&gt;| head 1&lt;/CODE&gt;, why you say that you received as result three strings?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;status system replication site "1": ERROR
status system replication site "3": ACTIVE
overall system replication status: ERROR.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In addition, in your example there isn't any row that matches the search string, so you should not have any result.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 07:48:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-log-for-alert/m-p/336707#M99900</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-12-12T07:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: Search log for alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-log-for-alert/m-p/336708#M99901</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;BR /&gt;
The full one log have 32 line. i only copy the 3 line. This is not the log. Only i export the command line to the log file and send his file to the splunk. The log content is:&lt;BR /&gt;
| SYSTEMDB | p-crm-db01 | 30601 | nameserver   |         1 |       2 | CRM01     | p-crm-db02 |     30601 |         1 | CRM02     | YES           | SYNC        | ACTIVE      |                                                                                                                                                                                                                                                            |&lt;BR /&gt;
| QP2      | p-crm-db01 | 30652 | indexserver  |         2 |       2 | CRM01     | p-crm-db02 |     30652 |         1 | CRM02     | YES           | SYNC        | ACTIVE      |                                                                                                                                                                                                                                                            |&lt;BR /&gt;
| RP2      | p-crm-db01 | 30640 | indexserver  |         2 |       2 | CRM01     | p-crm-db02 |     30640 |         1 | CRM02     | YES           | SYNC        | ACTIVE      |                                                                                                                                                                                                                                                            |&lt;BR /&gt;
| JP2      | p-crm-db01 | 30646 | indexserver  |         2 |       2 | CRM01     | p-crm-db02 |     30646 |         1 | CRM02     | YES           | SYNC        | ACTIVE      |                                                                                                                                                                                                                                                            |&lt;BR /&gt;
| CP2      | p-crm-db01 | 30643 | indexserver  |         2 |       2 | CRM01     | p-crm-db02 |     30643 |         1 | CRM02     | YES           | SYNC        | ACTIVE      |                                                                                                                                                                                                                                                            |&lt;BR /&gt;
| OP2      | p-crm-db01 | 30649 | indexserver  |         2 |       2 | CRM01     | p-crm-db02 |     30649 |         1 | CRM02     | YES           | SYNC        | ACTIVE      |                                                                                                                                                                                                                                                            |&lt;BR /&gt;
status system replication site "1": ACTIVE&lt;BR /&gt;
status system replication site "3": ERROR&lt;BR /&gt;
overall system replication status: ERROR&lt;/P&gt;

&lt;P&gt;Show that i  want to detect the log file about that: &lt;BR /&gt;
status system replication site "3": ACTIVE or ERROR. &lt;BR /&gt;
If i search the content about that: &lt;BR /&gt;
index=linux host="..." ("status system replication site "3": ACTIVE")&lt;BR /&gt;
the result is : &lt;BR /&gt;
status system replication site "1": &lt;STRONG&gt;ACTIVE&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;status system replication site "3"&lt;/STRONG&gt;: ERROR&lt;BR /&gt;
overall system replication status: ERROR&lt;/P&gt;

&lt;P&gt;This is false the result.&lt;BR /&gt;
Thank&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 09:08:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-log-for-alert/m-p/336708#M99901</guid>
      <dc:creator>dangtran</dc:creator>
      <dc:date>2017-12-12T09:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Search log for alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-log-for-alert/m-p/336709#M99902</link>
      <description>&lt;P&gt;Hi dangtran,&lt;BR /&gt;
beware that you have quotes in your strings so you have to escape them in searches&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=linux host="..." "status system replication site \"3\": ACTIVE"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;or use a rex command&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=linux host="..." | rex "status system replication site \"3\": ACTIVE"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;in this way you take only the row where you have &lt;CODE&gt;status system replication site "3": ACTIVE&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 14:53:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-log-for-alert/m-p/336709#M99902</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-12-12T14:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: Search log for alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-log-for-alert/m-p/336710#M99903</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;BR /&gt;
This working. Thank you very much.&lt;BR /&gt;
Have good day for you.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 15:44:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-log-for-alert/m-p/336710#M99903</guid>
      <dc:creator>dangtran</dc:creator>
      <dc:date>2017-12-12T15:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: Search log for alert</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-log-for-alert/m-p/336711#M99904</link>
      <description>&lt;P&gt;If you're satisfied, pleace accept or upvote my answer.&lt;BR /&gt;
By.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 16:02:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-log-for-alert/m-p/336711#M99904</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-12-12T16:02:25Z</dc:date>
    </item>
  </channel>
</rss>

