Splunk Search

search down sevices

aalaa
Path Finder

Hi ,

I have a list of services in my oracle server ,
i want to control the status of this services (Services Up and Services Down)
I create an alerte to give me the liste of the active services ( sourcetype=srvscript | stats count values(CMD) by _time |rename values(CMD) as "CMD" | where count < 7) and this worked fine ,
I want now to create an alerte to give me the services down , so i create a csv file contains the list of all existing services, and i want to compred with the search already created that gives the active services now,
I need a search that gives me the name of service not active (missing in search result of active services) ==> so how to compare the csv file contents and the active service result to find the non-active services ?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi aalaa,
if the field containing services is called "service", see something like this:

index=oracle sourcetype=srvscript 
| eval service=lower(service)
| stats count BY service
| append [ | inputlookup existingServices | eval count=0, service=lower(service) | fields count service ]
| stats sum(count) AS Total By service
| eval Status=if(Total=0,"Down","Up")
| sort service
| table service Status

You can also display this table in a graphic mode.

A little hint: use always the index=<your_index> option to have more performat searches.

Ciao.
Giuseppe

0 Karma

richgalloway
SplunkTrust
SplunkTrust

A subsearch should do it.

sourcetype=srcscript NOT [|inputlookup existingServices | format ]
---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...