Hi,
Today I am lack of knowledge... I have to build an availability report of a specific service on multiple servers. My Events look like as follows:
starttime, endtime, errorcode, servicename, servername
I would like to have a search result only when the error occurs on 4 servers at the same time.
I am confused how I can correlate the servername. My first try was
| where servername=server1 OR servername=server2.....
but this does not work... but concatenating with AND does not work neither....
Thank you guys, sorry for my foolery
You need the concurrency
command ( ... | where concurrency>=4
)
http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchReference/Concurrency
You need the concurrency
command ( ... | where concurrency>=4
)
http://docs.splunk.com/Documentation/Splunk/6.3.3/SearchReference/Concurrency
thanks thats it! 🙂 🙂 🙂
I would start trying with transaction and the number of events per transaction maybe??
maybe this works also, but in my case the concurrency command is the easier way... thanks anyway