Hello, noob user here with Flux working with InfluxDB 2 and Syslogs.
I’m looking to graph information based on what info I get in a syslog which has no numerical information. I’m pulling information out of the syslog message and generating new columns of data that basically interprets the state of the event. I’m then using stateDuration to get a time of how long the duration is between states.
This is an example where the _value column is the syslog message and I generate the state and ID columns by pulling values out of the message.
I can get a State Duration for “No Purging” and graph that. I want to be able to get a State Duration for Phase1 and Phase2 except that info is not in the message as it doesn’t identify which phase completed. However, the phases will complete in order so I’ve been trying to find a way to query which phase started on the previous event and fill in the state as that phase. Another option would be to compare the IDs and fill in the phase but I’ve not been able to get anything to work.
If I can get those two empty event fields filled in I can graph a complete time frame of how long each phase or no purge takes.
Any help would be greatly appreciated.