Splunk Search

How to search to organize vpn tunnel status table?

zen1tsu
Loves-to-Learn Lots

Good morning\afternoon\evening community!


I've met an issue with detecting vpn tunnel interface statuses which is identified by ping data inputs
can you give some ideas on how to organize the search to print table like below ?

on first table represented the logic of detecting the status of tunnel

zen1tsu_0-1673435280594.png

 


Thanks in advance, for any response!

 

 

0 Karma

zen1tsu
Loves-to-Learn Lots

destinations are randomly generated, output of icmp requests

sent=1 received=1 packet_loss=0 min_ping=0.397 avg_ping=0.397 max_ping=0.397 jitter=0.000 return_code=0 dest=167.68.156.4
sent=1 received=1 packet_loss=0 min_ping=0.397 avg_ping=0.397 max_ping=0.397 jitter=0.000 return_code=0 dest=90.239.46.155
sent=1 received=1 packet_loss=0 min_ping=0.397 avg_ping=0.397 max_ping=0.397 jitter=0.000 return_code=0 dest=180.206.119.58
sent=1 received=1 packet_loss=0 min_ping=0.397 avg_ping=0.397 max_ping=0.397 jitter=0.000 return_code=0 dest=6.37.163.174

 

0 Karma

zen1tsu
Loves-to-Learn Lots

for instance lets take
address A - 167.68.156.4
address B - 90.239.46.155
address C - 180.206.119.58
address D - 6.37.163.174

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @zen1tsu,

could you share saome sample data of your flow identifying the fields to use for grouping?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...