Dashboards & Visualizations

Sort and compare message_text - noob needs help

FinnHatlen
Engager

Hello, I have this new task that I'm not sure how to go about it. I'm new to splunk so any help is really appreciated. 

I want to create a dashboard that monitors all power issues that's been logged, as well as a dashboard for all remaining issues based on the message text below: 

host_name=Contoso* OR host_name=Kontoso* AND message_text="Power supply 1 has failed or been turned off"
OR message_text="Power supply 1 is okay" OR message_text="Power supply 2 has failed or been turned off" OR message_text="Power supply 2 is okay"
OR "Power-module 0/PS0/M1/SP failure condition cleared" OR "0/PS0/M1/SP, state: FAILED"

First off, the field "message_text" only captured four out of six messages, so these two were left out: 
"Power-module 0/PS0/M1/SP failure condition cleared" OR "0/PS0/M1/SP, state: FAILED"

I tried to see if i could create a new or update message_text to include these two, but it looked like it just added it to a new field that I couldn't find when I used the same filter afterwards. 

Is it here that I use the eval-function to compare and remove logs that has been cleared? 

Labels (1)
0 Karma

ashajambagi
Communicator

Hi @FinnHatlen 

If the other two values are added to some other field, you could write an eval and use coalesce function to include it in message_text.

https://docs.splunk.com/Documentation/Splunk/8.0.6/SearchReference/ConditionalFunctions#coalesce.28X...

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...