You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何基于起止日志在Splunk中创建可更新的文件执行成败统计图表/表格

你的需求完全可以在Splunk中实现,无需额外插件,仅通过原生SPL查询和仪表板配置就能满足。

实现步骤

1. 字段提取(可选,提前配置后查询更简便)

你可以提前在Splunk的字段提取中配置两类日志的解析规则,也可以直接在SPL中用rex命令实时提取:

  • 处理启动日志匹配规则:Processing file : (?<file_name>\S+),标记事件类型为processing
  • 处理成功日志匹配规则:Processed file successfully : (?<file_name>\S+),标记事件类型为success

2. 核心SPL查询语句

将语句中的索引、sourcetype替换为你实际的业务配置即可:

index=你的实际索引 sourcetype IN (处理日志的sourcetype, 成功日志的sourcetype)
# 实时提取文件名,提前配置过字段提取可删除下面两行rex
| rex "Processing file : (?<file_name>\S+)"
| rex "Processed file successfully : (?<file_name>\S+)"
# 标记事件类型、格式化日期
| eval event_type=if(searchmatch("Processing file"), "processing", "success")
| eval Date=strftime(_time, "%Y-%m-%d")
# 按文件名聚合,取每个文件的最新事件状态和对应日期
| stats latest(event_type) as latest_status latest(Date) as Date by file_name
# 生成你需要的成败标识字段
| eval Success=if(latest_status="success", "Yes", "No")
| eval Failure=if(Success="Yes", "No", "Yes")
# 输出指定格式的表格
| table Date file_name Success Failure
| rename file_name as "File Name"

3. 自动更新配置

把上述查询保存为仪表板面板,在面板设置中开启自动刷新,根据你的日志上报延迟选择刷新间隔(比如1分钟、5分钟)。面板每次刷新时会自动拉取最新日志,通过latest聚合逻辑自动更新文件的状态和对应日期,完全符合你要求的重处理成功后自动更新的效果。

内容的提问来源于stack exchange,提问作者ZZzzZZzz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 19:39:01