<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to search error message in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-search-error-message/m-p/495951#M8585</link>
    <description>&lt;P&gt;I tried but search.log shows only access log.&lt;/P&gt;</description>
    <pubDate>Tue, 12 May 2020 23:57:22 GMT</pubDate>
    <dc:creator>kanam</dc:creator>
    <dc:date>2020-05-12T23:57:22Z</dc:date>
    <item>
      <title>How to search error message</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-search-error-message/m-p/495947#M8581</link>
      <description>&lt;P&gt;When I search or after running saved search, sometimes error messages are displayed,&lt;BR /&gt;
however activity log shows they have been completed.&lt;BR /&gt;
"Dispatch Command: Unknown error for indexer: xxxx. Search Results might be incomplete! If this occurs frequently, please check on the peer."&lt;/P&gt;

&lt;P&gt;I want to search how frequently these message are created.&lt;BR /&gt;
Please let me know the way to search.&lt;/P&gt;

&lt;P&gt;I can't find as below.&lt;BR /&gt;
-index=_internal "&lt;EM&gt;dispatch&lt;/EM&gt;"&lt;BR /&gt;
-index=_internal "&lt;EM&gt;incomplete&lt;/EM&gt;"&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:23:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-search-error-message/m-p/495947#M8581</guid>
      <dc:creator>kanam</dc:creator>
      <dc:date>2020-09-30T05:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to search error message</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-search-error-message/m-p/495948#M8582</link>
      <description>&lt;P&gt;Search &lt;CODE&gt;index=_internal sourcetype=splunkd&lt;/CODE&gt; for the name of the indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 13:48:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-search-error-message/m-p/495948#M8582</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-05-11T13:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to search error message</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-search-error-message/m-p/495949#M8583</link>
      <description>&lt;P&gt;I've tried to search index=_internal sourcertype=splunkd in both SerchHead and Indexer, but I can't find the target error message.&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 00:03:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-search-error-message/m-p/495949#M8583</guid>
      <dc:creator>kanam</dc:creator>
      <dc:date>2020-05-12T00:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to search error message</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-search-error-message/m-p/495950#M8584</link>
      <description>&lt;P&gt;One other place to look is the search.log of any search that displays that message.&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 12:42:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-search-error-message/m-p/495950#M8584</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-05-12T12:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to search error message</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-search-error-message/m-p/495951#M8585</link>
      <description>&lt;P&gt;I tried but search.log shows only access log.&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2020 23:57:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-search-error-message/m-p/495951#M8585</guid>
      <dc:creator>kanam</dc:creator>
      <dc:date>2020-05-12T23:57:22Z</dc:date>
    </item>
  </channel>
</rss>

