LogLevel =“INFO”ServerName =“test”HEALTH_CHECK_STATUS =“OK”DATETIME =“29-3-2017 13:15:00”
LogLevel =“INFO”ServerName =“test”EALTH_CHECK_STATUS =“OK”DATETIME =“29-3-2017 13:20:00”
LogLevel =“INFO”ServerName =“test”HEALTH_CHECK_STATUS =“OK”DATETIME =“29-3-2017 13:25:00”
LogLevel =“INFO”ServerName =“test”HEALTH_CHECK_STATUS =“OK”DATETIME =“29-3-2017 13:30:00”
LogLevel =“INFO”ServerName =“test”HEALTH_CHECK_STATUS =“FAILED”DATETIME =“29-3-2017 13:35:00”
我正在尝试为HEALTH_CHECK_STATUS绘制图表。 需要帮助。我尝试使用时间表。但所有都需要数字作为输入。是否可以转换“OK”和“FAILED”并在splunk中绘制图形?
答案 0 :(得分:0)
index = myindex HEALTH_CHECK_STATUS | eval health = if(HEALTH_CHECK_STATUS =" OK",100,0)|时间表值(健康)为healthstatus