Does anyone use Splunk to capture statistics from their Legato back-ups?
Legato's mminfo reporting tool doesn't give me the information I need, but the e-mail sent out to us upon the completion of a saveset does. So I've been using Splunk to capture the mail spool for that account. This has actually worked pretty well. Thanks to some punct options I can produce an easier-to-read search result.
There are two things I'd like to do:
Legato has utilities that do this for us, but it would be very nice if we could get Splunk to do it. One stop shopping, right?
Date: Thu, 26 Aug 2010 05:23:23 -0400
From: root
Message-Id: <4798379873434.o87649853462@host.xyz.com>
To: oper
Subject: host1.xyz.com's savegroup completion
Cc: root
NetWorker savegroup: (alert) ProdDailycompleted, Total 8 client(s), 1 Failed, 7 Succeeded.
Please see group completion details for more information.
Failed: host1
Succeeded: host2, host3, host4, host5
Is what I'm asking for possible/practical? Or is this just not worth the effort?
Thanks!
Sure, it seems very easy. Most of the work will simply be in defining appropriate field extractions to get the data from your emails, and these look to be fairly straightforward regular expressions. If you're already getting the emails in Splunk, that's a big help. Make sure the time and "Failed" fields are extracted.