Splunk Search

Check latest status and print the reason on failure

Narmathavairava
Loves-to-Learn

Hi ,

 

I have the logs written in the below manner

26/08/2024 10:27 method=are status=failed run_id_123

26/08/2024 10:28 method=are status=failed run_id_123

26/08/2024 10:29 method=are status=failed run_id_123

26/08/2024 10:30 method=are status=completed run_id_123

failure_reason1

failure_reason_2

failure_reason_3

failure_reason_4

 

 

m trying to check the latest retry is completed or failed, if faile print the failure reason on the next 5 lines.

 

please help

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

It is not clear from this what you are expecting as your output. How do the failure_reason lines relate to the status lines?  Please can you share some actual events (anonymised as appropriate), preferably in a code block?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...