Hello Experts, I need help in resolving one of the issue that I am facing while trying to discard events that below to specific monitoring path. So here is the issue. Our requirement is such that we have to group servers based on application. Now when we are grouping them based on app, the server for which some path is not required to be monitored is also getting ingested since I am unable to selectivley monitor path based on app for any host. For example, I have app--> app1 and app2 with servers app1h1, app1h2 and app2h1,app2h2 respectively. Path to be monitored for app1 with host app1h1 and app1h2 is /var/log Path to be monitored for app2 with host app2h1 and app2h2 is /applogs/portal Now the issue is since both of these paths are present in all of these hosts so when we mention these paths in input file, for host app1h1 and app1h2 which was supposed to be monitored for /var/log only, also start sending logs under /applogs/portal and same go for app2h1 and app2h2 which also starts sending logs for /var/log rather than just sending it for /applogs/portal. We just want to achieve specific path to be monitored for host that are required. I checked for filtering out based on blacklist by using regex but it didn't work under monitoring stanza. Tried to find pattern where I can corelate events based on host so that I can write some regex, but that didn't seemed to work (for this I am not sure if what I have done was correct). Any help or suggestion would be really helpful. Thank you.
... View more
I have observed that some of my lookup files that are intended to get updated on daily basis by reports, does not always have latest data. I have used 2 approaches so far: 1) Used report add action feature to add data to lookup files.
2) Used Outputlookup command with append.
In both the cases, I have scheduled them to run on daily basis. But have observed that my lookup always do not gets updated (appended) with daily chunk of data. I have verified by running individual searches for the data availability for those particular days for which lookups were not added with data.
Can someone please help me in understanding at the possible cause behind this.
Thanks in advance.
... View more
Hi everyone, I need help in figuring out a way to use my report (table data) into calculations in my dashboard panel. I have a report that runs on daily basis and calculates avg response time of servers by environments (app name say ABC, def and xyz). Now I want to use this response time as an input to one of my panel's back end search. So report data is like below app name response time 1) ABC 0.234 sec 2) def 0.113 sec 3) xyz 0.227 sec I want to use this response time to build gauge in my dashboard panel. I have added this report in my dashboard panel that gives in a search ref tag but I don't know how to use this further.
... View more