Hello,
I make a script that retourne a certificats list in Excel form then I display uniquely the certifcat about to expire with a validity days.
But I would like to display " No certificat about to expire" if no value are find and not the message below. Do you know if it is possible ?
index = "index_pki" sourcetype = "splunk_csv" AND (Template=FVE_ServerWeb OR Template=1.3.6.1.4.1.311.21.8.4247237.15172642.2378160.7384375.2155270.77.16524867.13256529 OR Template=FVE_ServerWeb_2Years)
| fields ReqID CN Template Validity NotAfter NotBefore San Tumbprint Requester_Name |dedup ReqID CN
| where Validity < 30
| sort Validity
| table ReqID CN Template Validity NotAfter NotBefore San Tumbprint Requester_Name
Thank you
Regards,
Miguel
The appendpipe command usually is used for that.
index = "index_pki" sourcetype = "splunk_csv" AND (Template=FVE_ServerWeb OR Template=1.3.6.1.4.1.311.21.8.4247237.15172642.2378160.7384375.2155270.77.16524867.13256529 OR Template=FVE_ServerWeb_2Years)
| fields ReqID CN Template Validity NotAfter NotBefore San Tumbprint Requester_Name |dedup ReqID CN
| where Validity < 30
| appendpipe [ stats count | eval Validity=0, ReqID="No certificat about to expire" | where count=0 | fields - count ]
| sort Validity
| table ReqID CN Template Validity NotAfter NotBefore San Tumbprint Requester_Name
The appendpipe command usually is used for that.
index = "index_pki" sourcetype = "splunk_csv" AND (Template=FVE_ServerWeb OR Template=1.3.6.1.4.1.311.21.8.4247237.15172642.2378160.7384375.2155270.77.16524867.13256529 OR Template=FVE_ServerWeb_2Years)
| fields ReqID CN Template Validity NotAfter NotBefore San Tumbprint Requester_Name |dedup ReqID CN
| where Validity < 30
| appendpipe [ stats count | eval Validity=0, ReqID="No certificat about to expire" | where count=0 | fields - count ]
| sort Validity
| table ReqID CN Template Validity NotAfter NotBefore San Tumbprint Requester_Name
Hello,
Thank you, it's work perfectly 😃