All Apps and Add-ons

how to see multiple file names in Spunk with there status

sunnyparmar
Communicator

Hi Guys,

I have multiple .xml files, around 1100 and all files have the status of either negative or positive in logs so I want to search all files on Splunk in a one go corresponding there status. Any insights would be appreciated.

Thanks in Advance
Ankit

0 Karma

burwell
SplunkTrust
SplunkTrust

Hello. Please provide sample logs.

0 Karma

sunnyparmar
Communicator

In case of Negative acknowledgement getting these two errors in log for the same file -

841392-1538181685-12005_ehfd.jcloud.no.xml - Returned negative MDN ERROR: and Unable to persist XML document

For positive acknowledgment, logs generating -> status=ok

Thanks in advance..

0 Karma

burwell
SplunkTrust
SplunkTrust

I am not quite understanding this. Is there a log with the above lines? Can you show us a sample of the exact lines so we can help?

It looks like there is no date or timestamp in the above, for example.

Thanks.

0 Karma

sunnyparmar
Communicator

Hi @burwell,

Could you please help me out. Waiting for your help.

Thanks
Ankit

0 Karma

sunnyparmar
Communicator

In case of OK acknowledgement -

2018-09-29 00:41:25,590 [AS2Servlet.java] [http-bio-8080-exec-358] [DEBUG] [eu.peppol.inbound.server.AS2Servlet] Served request, status=OK:

In case of ERROR acknowledgment -

2018-09-29 00:01:57,418 [InboundMessageReceiver.java] [http-bio-8080-exec-358] [ERROR] [eu.peppol.as2.InboundMessageReceiver] Unexpected error: Unable to persist XML document for PeppolMessageMetaData
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...