Splunk Search

Missing settlement notification

Sekhar
Explorer

Event and Report extract rules

Use the payment business events to identify Transactions which have ACCP clearing status (NPP 1012.NPP 1013) with missing Settlement Notification event NPP 1040

"NPP 1033_CR_INBOUND "NPP 1012 CECARING_INBOUND"

• "NPP 1013_RETURN_INBOUND" I

"NPP 1040 SETTLEMENT RECEIVED" Report should include the following fields

Time from NPP 1033

TXID from NPP 1033 Amount from NPP 1012 or NPP 1013

 

Already i have created query 

 

index-nch_apps_nonprod applications fis-npp source fis-npp-sit4 ((NPP 1012 CLEARING INBOUND OR NPP 1013 RETURN INBOUND) OR NPP 1033 CR INBOUND or

rex field-message "eventName=\"(?<eventName> *?)\"."

rex field-message "txId\"(?<txId>. *?)\,"

Κ

I rex field-message "amt=\"(?<amt>.2)\"." rex field-message ibm.datetime-(?<ibm_datetime> *),"

+

Participant

1 eval Participant substr(txId,1,8)

stats values(eventName) as eventName, min(ibt datetime) as Time, values(amt) as amt by (eventName, NPP 1840 SETTLEMENT RECEIVED) < 0 table Time eventName Participant amt

where mycount (eventName)

>= 3 AND mvfind (eventName, npp 1040) but not getting any result 

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Please edit your query to use code blocks

bowesmana_0-1695714501872.png

</> to format it - as it stands is almost impossible to work out what is your query - plenty of strange things in there, including a random K and a plus sign and seemingly missing pipe symbols as well as missing double quotes where they would be expected and stats clauses that don't make a lot of sense.

 

 

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...