Hi Giuseppe, Thank you for your response. My data has both the Running and Stopped Service. Splunk detects both service status. The only issue is Spunk detects all services as the same value. We do not want to use a csv file though. What the script does is it takes all the services, status and all details we require. Then it logs to a log file. We then have a .conf file that does the regex to parse the data. So for example, in Splunk dashboard, it shows Service A = Running, Service B = Stopped. However, it cannot be identified in the Dashboard. The Dashboard displays both services with the same color. Once again, thank you for your response 🙂
... View more