All Apps and Add-ons

how to see multiple file names in Spunk with there status

sunnyparmar
Communicator

Hi Guys,

I have multiple .xml files, around 1100 and all files have the status of either negative or positive in logs so I want to search all files on Splunk in a one go corresponding there status. Any insights would be appreciated.

Thanks in Advance
Ankit

0 Karma

burwell
SplunkTrust
SplunkTrust

Hello. Please provide sample logs.

0 Karma

sunnyparmar
Communicator

In case of Negative acknowledgement getting these two errors in log for the same file -

841392-1538181685-12005_ehfd.jcloud.no.xml - Returned negative MDN ERROR: and Unable to persist XML document

For positive acknowledgment, logs generating -> status=ok

Thanks in advance..

0 Karma

burwell
SplunkTrust
SplunkTrust

I am not quite understanding this. Is there a log with the above lines? Can you show us a sample of the exact lines so we can help?

It looks like there is no date or timestamp in the above, for example.

Thanks.

0 Karma

sunnyparmar
Communicator

Hi @burwell,

Could you please help me out. Waiting for your help.

Thanks
Ankit

0 Karma

sunnyparmar
Communicator

In case of OK acknowledgement -

2018-09-29 00:41:25,590 [AS2Servlet.java] [http-bio-8080-exec-358] [DEBUG] [eu.peppol.inbound.server.AS2Servlet] Served request, status=OK:

In case of ERROR acknowledgment -

2018-09-29 00:01:57,418 [InboundMessageReceiver.java] [http-bio-8080-exec-358] [ERROR] [eu.peppol.as2.InboundMessageReceiver] Unexpected error: Unable to persist XML document for PeppolMessageMetaData
0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...