Splunk Search

How to calculate Uptime?

amandeepsingh
Explorer

Splukers,

I want to calculate uptime for my network. By this I mean, I need uptime in hours like time diffrence between to consecutive uptimes and downtimes. 

amandeepsingh_0-1596505846572.png

 

As in above image, I want to calculate uptime and downtime but not total. for example my network was up for two hours and there was downtime for 15 mins and then network is up for 4 hours and then again experience downtime for 10 mins. I want to achieve this. How can I do this stuff in SPL

Labels (3)
0 Karma

amandeepsingh
Explorer

I am stil stuck here.. Any one can help me here.

Tags (1)
0 Karma

amandeepsingh
Explorer

Is this post is being viewed.. Anyone help me here?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

Your question is not clear with respect to events you shared. Can you elaborate little bit with example.

————————————
If this helps, give a like below.
0 Karma

amandeepsingh
Explorer

Yeah!! actually I want to monitor my public IP.. let's say google.. so I am pinging that IP..

and saving those into txt file. Then I am inserting those txt files into splunk.

Now, Network might be Up for like 3 hours and down for next 10 min and then again up for 2 hours.

so what is want as per below image.. Instead of arrow you can count it up and down

amandeepsingh_0-1596599399920.png

 

Tags (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

I believe there are many dest in your events. You want to get this report per dest?

————————————
If this helps, give a like below.
0 Karma

amandeepsingh
Explorer

yes! i have configured drill down to each dest. So i want it on the dril down page..

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...