<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search string and evaluate the string in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554861#M702</link>
    <description>&lt;P&gt;Thank you a lot&lt;/P&gt;</description>
    <pubDate>Tue, 08 Jun 2021 09:09:54 GMT</pubDate>
    <dc:creator>agamnarendra</dc:creator>
    <dc:date>2021-06-08T09:09:54Z</dc:date>
    <item>
      <title>Search string and evaluate the string</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554825#M696</link>
      <description>&lt;P&gt;I need to findout errorcodes from logs and segregate them. Below log file is one of example logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t"&gt;2021-06-08T05:42:29.141140&lt;/SPAN&gt;&lt;SPAN&gt;+&lt;/SPAN&gt;&lt;SPAN class="t"&gt;00:00&lt;/SPAN&gt; &lt;SPAN class="t"&gt;DEBUG&lt;/SPAN&gt; &lt;SPAN class="t"&gt;html5client-v3&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN class="t"&gt;19206&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt; [&lt;/SPAN&gt;&lt;SPAN class="t"&gt;xid@1192&lt;/SPAN&gt; &lt;SPAN class="t"&gt;xid=S2TF6U5T&lt;/SPAN&gt;&lt;SPAN&gt;--&lt;/SPAN&gt;&lt;SPAN class="t"&gt;7&lt;/SPAN&gt; &lt;SPAN class="t"&gt;cid=Arris-110_20F19EB3C050&lt;/SPAN&gt; &lt;SPAN class="t"&gt;did=&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sid=5kCrKTc-K-4&lt;/SPAN&gt; &lt;SPAN class="t"&gt;hid=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;19206&lt;/SPAN&gt;&lt;SPAN&gt;"] &lt;/SPAN&gt;&lt;SPAN class="t"&gt;CONSOLE:0&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;null&lt;/SPAN&gt;&lt;SPAN&gt;) &lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;06-08-2021&lt;/SPAN&gt; &lt;SPAN class="t"&gt;05:42:29.141&lt;/SPAN&gt; &lt;SPAN class="t"&gt;DEBUG&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class="t"&gt;SGUI.VENONA_ANALYTICS&lt;/SPAN&gt;&lt;SPAN&gt;){"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;action&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;error&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;data&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;{"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;category&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;error&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;triggeredBy&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;application&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;errorCode&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;GEN-1016&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t a"&gt;&lt;SPAN class="t"&gt;errorType&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;application&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;errorMessage&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;We&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;re&lt;/SPAN&gt; &lt;SPAN class="t"&gt;sorry&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class="t"&gt;we&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN class="t"&gt;re&lt;/SPAN&gt; &lt;SPAN class="t"&gt;unable&lt;/SPAN&gt; &lt;SPAN class="t"&gt;to&lt;/SPAN&gt; &lt;SPAN class="t"&gt;load&lt;/SPAN&gt; &lt;SPAN class="t"&gt;your&lt;/SPAN&gt; &lt;SPAN class="t"&gt;subscription&lt;/SPAN&gt; &lt;SPAN class="t"&gt;info.&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Please&lt;/SPAN&gt; &lt;SPAN class="t"&gt;try&lt;/SPAN&gt; &lt;SPAN class="t"&gt;again&lt;/SPAN&gt; &lt;SPAN class="t"&gt;later.&lt;/SPAN&gt; &lt;SPAN class="t"&gt;\nReference&lt;/SPAN&gt; &lt;SPAN class="t"&gt;Code:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;amp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;nbsp&lt;/SPAN&gt;&lt;SPAN&gt;;&amp;amp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;nbsp&lt;/SPAN&gt;&lt;SPAN&gt;;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;GEN-1016&lt;/SPAN&gt;&lt;SPAN&gt;","&lt;/SPAN&gt;&lt;SPAN class="t"&gt;success&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class="t"&gt;:false&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 06:18:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554825#M696</guid>
      <dc:creator>agamnarendra</dc:creator>
      <dc:date>2021-06-08T06:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: Search string and evaluate the string</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554835#M697</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex "\"errorCode\":\"(?&amp;lt;errorCode&amp;gt;[^\"]+)"&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 08 Jun 2021 06:54:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554835#M697</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-08T06:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: Search string and evaluate the string</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554839#M698</link>
      <description>&lt;P&gt;index=platform sourcetype=cloudtvapp NOT (host="*dev*")&lt;BR /&gt;| rex "\"errorCode\":\"(?&amp;lt;errorCode&amp;gt;[^\"]+)"&lt;BR /&gt;| table errorCode cid&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you for quick response&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its not printing the errorCode with respective cid value. Search and filter is happened but not printed with above search. Any inputs?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 07:08:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554839#M698</guid>
      <dc:creator>agamnarendra</dc:creator>
      <dc:date>2021-06-08T07:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: Search string and evaluate the string</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554842#M699</link>
      <description>&lt;P&gt;Is cid being extracted automatically or do you need to extract as part of your search?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 07:24:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554842#M699</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-08T07:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Search string and evaluate the string</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554849#M700</link>
      <description>&lt;P&gt;Below search was helped to get the desired out put. but need to errorType filter in "rex". Can you guide me&lt;BR /&gt;&lt;BR /&gt;index=platform sourcetype=cloudtvapp NOT (host="*dev*" OR host="*zod*")&lt;BR /&gt;| rex "\"errorCode\":\"(?&amp;lt;errorCode&amp;gt;[^\"]+)"&lt;BR /&gt;| search errorCode="*"&lt;BR /&gt;| stats count(errorCode) by errorCode host&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cid was added automatically . But need to "errorType" and "errorMessage" with respective&amp;nbsp; filter in "rex". Can you guide me&lt;BR /&gt;&lt;BR /&gt;Basically i need to add more than one field search in "rex"&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 08:06:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554849#M700</guid>
      <dc:creator>agamnarendra</dc:creator>
      <dc:date>2021-06-08T08:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Search string and evaluate the string</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554852#M701</link>
      <description>&lt;LI-CODE lang="markup"&gt;index=platform sourcetype=cloudtvapp NOT (host="*dev*" OR host="*zod*")
| rex "\"errorCode\":\"(?&amp;lt;errorCode&amp;gt;[^\"]+)\",\"errorType\":\"(?&amp;lt;errorType&amp;gt;[^\"]+)\",\"errorMessage\":\"(?&amp;lt;errorMessage&amp;gt;[^\"]+)"
| search errorCode="*"
| stats count values(errorType) as errorType values(errorMessage) as errorMessage by errorCode host&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 08 Jun 2021 08:15:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554852#M701</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-06-08T08:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Search string and evaluate the string</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554861#M702</link>
      <description>&lt;P&gt;Thank you a lot&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jun 2021 09:09:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Search-string-and-evaluate-the-string/m-p/554861#M702</guid>
      <dc:creator>agamnarendra</dc:creator>
      <dc:date>2021-06-08T09:09:54Z</dc:date>
    </item>
  </channel>
</rss>

