Splunk IT Service Intelligence
Highlighted

I had a issue with Splunk server Availability Query. Can anyone check and correct me?

New Member

Hi All,

I had a issue with Splunk server Availability Query. Can anyone check and correct me?

index=itsisummary kpi="Splunk Agent Availability" NOT "entitytitle=serviceaggregate"
| eval test = replace(alert
value, "N.A", "1")
| stats sum(test) as off dc(datemday) as day by entitytitle
| eventstats max(day) as maxday
| eval max = max
day1440
| eval server_off = off
5
| eval percentoff = (serveroff / max) * 100
| eval percenton = 100 - percentoff
| table entitytitle, percent* day serveroff
| rename entitytitle as Host percentoff as "Unavailability Percentage" percenton as "Availability Percentage" day as "Number of running days" serveroff as "Server Unavailable in Minutes"

Thanks in Advance!!

0 Karma
Highlighted

Re: I had a issue with Splunk server Availability Query. Can anyone check and correct me?

SplunkTrust
SplunkTrust

What results are you getting and what are the expected results?

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: I had a issue with Splunk server Availability Query. Can anyone check and correct me?

I didn't find the results. I want to see the results till date. Any changes need to done in query?

Regards,
Raj

0 Karma
Highlighted

Re: I had a issue with Splunk server Availability Query. Can anyone check and correct me?

SplunkTrust
SplunkTrust

It's difficult to determine the correctness of a query without knowing the data being searched as well as the desired output.

There are, however, some problems with the query. Some may be the result of errors entering the query into the question.

The table command makes only 4 fields available, but the following rename command attempts to rename two fields that no longer exist (percentoff, percenton).

The base query is searching for the string "entitytitle=serviceaggregate". Perhaps it intends to search for the field entitytitle containing the value "serviceaggregate" (entity_title="service_aggregate").

The calculation of percent_off is missing a * character.

The field server_off claims to be in minutes, but is multiplied by 5 for no apparent reason.

Please verify the alert_value field contains "N.A" and not "N/A".

---
If this reply helps you, an upvote would be appreciated.
0 Karma