Splunk Search

return: eval filename=strftime(now(), with yesterdays count (as fileinformation)

Explorer

hello,

looking for some help.

I am running a search, daily.... but the logs in the source get updated late by the application (the app updates the source/log-file next day with values related to previous day) , so I want to run my search next day and return the result into an outputlookup.csv incl. the day-count of previous day.

in example: if my search runs daily ... let's say on day 9 (search is on previous day (8 = yesterday) it returns an outputlookup .csv as: file-name%d.csv which is equal as file-name09.csv (works perfectly)

I need to get it returned as: file-name_08.csv

below search I am using:

index="application-license" sourcetype=application LicenseUserdevice=* Licensefeaturestatus="OUT" Licenseuser=*
| eval License
featurestatus=(Licensefeaturestatus)
| eval License
Userdevice=split(LicenseUserdevice,",")
| eval License
user=split(Licenseuser,",")
| makemv delim="," License
user
| mvexpand Licenseuser
| sort License
user
| dedup Licenseuser
| stats list(License
user) as "User" list(LicenseUserdevice) as "Computer" count(Licensefeaturestatus) as "LicenseTaken" by _time

| outputlookup [ | stats count | eval filename=strftime(now(), "Application-license-usage-perday%d.csv") | return $filename]

...................

I tried (without results):

| outputlookup [ | stats count | eval filename=strftime((now(),"-1d"), "Minitab-license-usage-perday%d.csv") | return $filename]
or
| outputlookup [ | stats count | eval filename=relative_time(now(), "-1d@d"), "%m/%d") | return $filename]


do you have any idea / solution for me?

thx in advance
Kai

0 Karma

Influencer
0 Karma