Hello! A team at my organization is concerned with MongoDB 4.2 running on my splunk hosts and want me to create a plan to upgrade them to 6.0 at a minimum. From what I've read it seems like this is either not possible or a bad idea due to possible modifications that have been done by splunk. Is there a documented way to upgrade to MongoDB 6.0 or newer? Thanks.
... View more
Most recent first is what I want, I think. What I mean by until is for that variable to be set to 0 once an event with xa recovery is received then that variable stays the same regardless of the other events that are received until an event is received that has System READY in the event then it'll go back to the original value 1. I'll try what you have there with streamstats.
... View more
Hello! I currently have this eval in a search of mine:
| eval exists=if(like(_raw, "%xa recovery%"), 0, 1)
Is there any way to set the variable exists to 0 until a specific event comes up? What I'm trying to accomplish is like this... If event contains(xa recovery) exists=0 until event contains(System READY) then exists=1.
Thank you!
... View more