Dashboards & Visualizations

Display count of the Life Cycle events per Request Id (RID)

aditsss
Motivator

Hi Everyone,

Below are my logs:

RID:492e0bd2-d3c4-4d28-a318-c4aee5f4e0-of1-team_a-dmrupload ARC_EL:ARC_1100:  EVENT RECEIVED FROM SOURCE 

This is the RID 492e0bd2-d3c4-4d28-a318-c4aee5f4e0 that I have extracted from the logs:

My search query:

index=ABCns=XYZ app_name=api  22abe6c4-6eaf-4d47-8c4a-79b2594e

 Each RID has gone through  different events like for this RID"22abe6c4-6eaf-4d47-8c4a-79b2594e" as we have seen in the below logs it has gone through the events like "ARC SUCCESSFULLY UPDATED RESPONSE BACK TO SOURCE OR SF" and "ARC SUCCESSFULLY RECEIVED RESPONSE FROM TARGET" etc.

2020-09-30T05:03:34.604056922Z app_name=ABC environment=e1ns=HJ pod_container=api pod_name=deployment-20-lmkq6 message=2020-09-29 22:03:34.602 INFO [blaze-arc-service,,,] 1 --- [ elastic-3] c.a.b.a.c.s.impl.SFCallbackService : RID:22abe6c4-6eaf-4d47-8c4a-79b2594ea612-of1-team_g ARC_EL:ARC_1600: ARC SUCCESSFULLY UPDATED RESPONSE BACK TO SOURCE OR SF

2020-09-30T05:03:34.604056922Z app_name=ABC environment=e1ns=HJ pod_container=api pod_name=deployment-20-lmkq6 message=2020-09-29 22:03:34.602 INFO [blaze-arc-service,,,] 1 --- [ elastic-3] c.a.b.a.c.s.impl.SFCallbackService : RID:22abe6c4-6eaf-4d47-8c4a-79b2594ea612-of1-team_g ARC_EL:ARC_1600: ARC SUCCESSFULLY RECEIVED RESPONSE FROM TARGET

what I want is now when I click on one particular RID suppose as a hyperlink it should open the events and if the RID has gone through the events it should be right tick otherwise cross.

Below are my events:

  • ARC EVENT RECEIVED FROM SOURCE 
  • ARC FAILED TO INVOKE TARGET END POINT 
  • ARC SUCCESSFULLY RECEIVED RESPONSE FROM TARGET 
  • ARC FAILED TO RECEIVE RESPONSE FROM TARGET 
  • ARC SUCCESSFULLY UPDATED RESPONSE BACK TO SOURCE OR SF 
  • ARC FAILED TO UPDATE RESPONSE BACK TO SOURCE OR SF 
  • ARC FAILED TO DOWNLOAD FILE FROM SOURCE OR SF 
  • ARC S3 UPLOAD FAILED 

 

Is that possible in splunk?

Can someone guide me on that.

Labels (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

yes, its possible with custom js.

————————————
If this helps, give a like below.
0 Karma

aditsss
Motivator

@thambisetty 

 

I cant use custom Js. Apart from JS is that possible.

 

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...