Dashboards & Visualizations

How do you visualize a topology with mentioned logs?

dhirendra761
Contributor

Hi Splunkers,

I have below a type of data in our log files:

System export of 3.FR successfully transferred to 2.SP
System Import successfully ended on 3.FR from export of 2.SP with exit code 0
System export successfully ended on 2.SP with exit code 0

which means that "A Line will be drawn towards from 3.FR to 2.SP boxes with OK and vice versa.

Please refer to the below image for more info.

Could you please suggest which approach needs to follow in order to achieve the below topology graph?

I am trying a lot, but not succeeding. Any help will be appreciated. Thanks.
alt text

0 Karma
1 Solution

woodcock
Esteemed Legend

You need a custom visualization (AKA modviz). Here are some that you can try:
https://splunkbase.splunk.com/app/4346/
https://splunkbase.splunk.com/app/3762/
https://splunkbase.splunk.com/app/3112/
https://splunkbase.splunk.com/app/277/
https://splunkbase.splunk.com/app/3379/
https://splunkbase.splunk.com/app/3843/
https://splunkbase.splunk.com/app/3767/
ALSO. Please check out the Splunk Business Flow beta, which will probably also meet your needs (and if not, you can influence the evolution of the project):
https://www.splunk.com/en_us/software/splunk-next.html

View solution in original post

0 Karma

woodcock
Esteemed Legend

You need a custom visualization (AKA modviz). Here are some that you can try:
https://splunkbase.splunk.com/app/4346/
https://splunkbase.splunk.com/app/3762/
https://splunkbase.splunk.com/app/3112/
https://splunkbase.splunk.com/app/277/
https://splunkbase.splunk.com/app/3379/
https://splunkbase.splunk.com/app/3843/
https://splunkbase.splunk.com/app/3767/
ALSO. Please check out the Splunk Business Flow beta, which will probably also meet your needs (and if not, you can influence the evolution of the project):
https://www.splunk.com/en_us/software/splunk-next.html

0 Karma

dhirendra761
Contributor

Hi All/ @woodcock

I am using below SPL:

host="ITEM-System" sourcetype="System"
 | rex "System \s+(?<action>\w+) of (?<from_server>.*) (?<result>successfully|failed) transferred to (?<to_server>.*)"
 | rex "System \s+(?<action>\w+) (?<result>successfully|failed) ended on (?<from_server>.*) from export of (?<to_server>.*) with exit code 0"|eval linkType=case(action="export","licensing",action="Import","search"), result="OK"|table from_server action to_server result linkType| where action!=" "

and genrated the attached visualization trough with Network Topology - Custom Visualization App.

Could you please suggest more on SPL for better display.

Thanks.alt text

0 Karma

woodcock
Esteemed Legend

You are just going to have to play around with it. I have never used them.

0 Karma

dhirendra761
Contributor

Thanks a lot @woodcock . 🙂

0 Karma

dhirendra761
Contributor

Sure, I will try with mentioned apps and get back to you. Thank you very much for your suggestion.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...