I don't understand the part with eval (what we calculate and for what):
| inputlookup meta_woot where index=* sourcetype=* host=*
| where recentTime<(now()-3600)
| eval latency= round((recentTime-lastTime)/60,2)
| eval latency_type=if(latency<0,"Logging Ahead","Logging Behind")
| eval latency=abs(latency)
| eval latency_type=if(latency="0.00","No Latency",latency_type)
| where latency>=0
| convert ctime(recentTime) ctime(firstTime) ctime(lastTime) ctime(lastUpdated)
| rename latency AS "latency (mins)"
| table index, sourcetype, host, firstTime, lastTime, recentTime, "latency (mins)",latency_type, lastUpdated
| sort - "latency (mins)"
— — — — — — — — — — — — — — — — — — — — — — — —
And what mean:
| rest splunk_server=* /services/server/info
From savedsearches.conf
[Generate Meta Woot Server GUID Lookup]
disabled = 1
action.email.useNSSubject = 1
alert.digest_mode = True
alert.suppress = 0
alert.track = 0
auto_summarize.dispatch.earliest_time = -1d@h
cron_schedule = 0 0 * * *
enableSched = 1
search = | rest splunk_server=* /services/server/info | fields splunk_server, guid\
| outputlookup meta_woot_server_guid
For what we need fields splunk_server, guid ?
... View more