Knowledge Management

Summerize in reports - is it possible ?

sbeamro
Explorer

Hi,
I'm trying to set a weekly report on Severity Level 1 etc of syslog information.
since there are equipment that sends the information every few minutes (which makes sense it is severity level 1) - I'd like to summerize that into 1 line (that can or can't be expandable).
for example -

> host = 10.40.2.148 severity_id = 1
> source = udp:514 sourcetype =
> cisco:ios 1/18/15  1:30:13.000 PM  Jan
> 18 13:30:13 10.40.2.148 55888: Jan 18
> 11:30:09: %PLATFORM_ENV-1-PWR: Faulty
> internal power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 1:20:51.000 PM     Jan 18 13:20:51
> 10.40.2.148 55887: Jan 18 11:20:46: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 1:18:54.000 PM     Jan 18 13:18:54
> 10.40.2.148 55886: Jan 18 11:18:50: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 1:14:09.000 PM     Jan 18 13:14:09
> 10.40.2.148 55885: Jan 18 11:14:05: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 1:14:04.000 PM     Jan 18 13:14:04
> 10.40.2.148 55884: Jan 18 11:14:00: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 1:09:18.000 PM     Jan 18 13:09:18
> 10.40.2.148 55883: Jan 18 11:09:14: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 12:57:22.000 PM    Jan 18 12:57:22
> 10.40.2.148 55882: Jan 18 10:57:18: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 12:48:14.000 PM    Jan 18 12:48:14
> 10.40.2.148 55881: Jan 18 10:48:09: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected host =
> 10.40.2.148 severity_id = 1 source = udp:514 sourcetype = cisco:ios 1/18/15
> 12:46:40.000 PM    Jan 18 12:46:40
> 10.40.2.148 55880: Jan 18 10:46:36: %PLATFORM_ENV-1-PWR: Faulty internal
> power supply detected

can I make it into 1 line ? (summary)

Tags (2)
0 Karma

kendrickt
Path Finder

Hi sbeamro,

Have you tried using a macro?

http://docs.splunk.com/Documentation/Splunk/6.2.1/Search/Usesearchmacros

Alternatively, you can add the search to a dashboard table and click on the dashboard to view it.

Thanks!

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...