Hi,
I'm trying to set a weekly report on Severity Level 1 etc of syslog information.
since there are equipment that sends the information every few minutes (which makes sense it is severity level 1) - I'd like to summerize that into 1 line (that can or can't be expandable).
for example -
> host = 10.40.2.148 severity_id = 1
> source = udp:514 sourcetype =
> cisco:ios 1/18/15 1:30:13.000 PM Jan
> 18 13:30:13 10.40.2.148 55888: Jan 18
> 11:30:09: %PLATFORM_ENV-1-PWR: Faulty
> internal power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 1:20:51.000 PM Jan 18 13:20:51
> 10.40.2.148 55887: Jan 18 11:20:46: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 1:18:54.000 PM Jan 18 13:18:54
> 10.40.2.148 55886: Jan 18 11:18:50: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 1:14:09.000 PM Jan 18 13:14:09
> 10.40.2.148 55885: Jan 18 11:14:05: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 1:14:04.000 PM Jan 18 13:14:04
> 10.40.2.148 55884: Jan 18 11:14:00: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 1:09:18.000 PM Jan 18 13:09:18
> 10.40.2.148 55883: Jan 18 11:09:14: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 12:57:22.000 PM Jan 18 12:57:22
> 10.40.2.148 55882: Jan 18 10:57:18: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 12:48:14.000 PM Jan 18 12:48:14
> 10.40.2.148 55881: Jan 18 10:48:09: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 12:46:40.000 PM Jan 18 12:46:40
> 10.40.2.148 55880: Jan 18 10:46:36: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected
can I make it into 1 line ? (summary)
Hi sbeamro,
Have you tried using a macro?
http://docs.splunk.com/Documentation/Splunk/6.2.1/Search/Usesearchmacros
Alternatively, you can add the search to a dashboard table and click on the dashboard to view it.
Thanks!