Splunk Search

Need help in displaying results in column

nicksrulz
Explorer

Hi Legends,

Need help in displaying start time, when error occurred and end time when it got resolved , in separate column. Currently they are getting displayed in same column like below :

statusDateTimeREASON_CODE
FAILED25/04/202325/04/2023 20:33Z910
FAILED25/04/202325/04/2023 20:11Z910
FAILED25/04/202325/04/2023 3:38Z911
FAILED25/04/202325/04/2023 3:37Z911
FAILED25/04/202325/04/2023 3:37Z911
FAILED25/04/202325/04/2023 3:36Z911

 

Please let me know how can i modify my query to display results like below:

StatusDateStart TimeEnd TimeREASON_CODECount
FAILED25/04/202325/04/2023 20:1125/04/2023 20:33Z9102
FAILED25/04/202325/04/2023 3:3625/04/2023 3:38Z9114

 

My Query :

index=test sourcetype="*" STATUS_REASON_CODE IN (U220, U902, U904, U905, Z704, Z900, Z902, Z903, Z904, Z910, Z911, Z912, Z913, Z914, Z920, Z922, Z923, Z924) STATE = FAILED | fields STATE _time STATUS_REASON_CODE | convert timeformat="%Y-%m-%d %H:%M:%S" ctime(_time) AS Time | convert timeformat="%Y-%m-%d" ctime(_time) AS TimeDay | eval FailTime=case(field_name="Failure Time", _time) | eval ReasonCode=case(field_name="Reason Code", STATUS_REASON_CODE) | eval State=case(field_name="State", STATE) | eval minTime = (min(Time)) | rename STATUS_REASON_CODE as REASON_CODE | sort - Time | table STATE TimeDay minTime REASON_CODE

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @nicksrulz,

let me understand: you want, for each REASON_CODE, the first event date and the last event date, is it correct?

if this is your requirement, please try this:

index=test sourcetype="*" STATUS_REASON_CODE IN (U220, U902, U904, U905, Z704, Z900, Z902, Z903, Z904, Z910, Z911, Z912, Z913, Z914, Z920, Z922, Z923, Z924) STATE=FAILED 
| rename STATUS_REASON_CODE as REASON_CODE 
| stats 
   values(STATE) AS Status
   earliest(_time) AS StartTime
   latest(_time) AS EndTime
   count
   BY REASON_CODE
| eval Date=strftime(StartTime,"%d/%m/%Y")
| table Status Date StartTime EndTime REASON_CODE count

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...