<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP error table in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Creating-a-table-but-it-shows-3-column-error-msg/m-p/597061#M48958</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp; Thank you for your input. Can you please elaborate on how can I extract separately?&lt;/P&gt;</description>
    <pubDate>Tue, 10 May 2022 05:16:46 GMT</pubDate>
    <dc:creator>Khanu89</dc:creator>
    <dc:date>2022-05-10T05:16:46Z</dc:date>
    <item>
      <title>Creating a table, but it shows 3 column error msg?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Creating-a-table-but-it-shows-3-column-error-msg/m-p/597053#M48956</link>
      <description>&lt;P&gt;I am trying to create a table which shows 3 column error msg, errorcode, and count. my current query is pulling the errorcode/msg in one column and error count&amp;nbsp; individually instead of whole. Please assist.&lt;/P&gt;
&lt;P&gt;my Current Query&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="My current query" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19533i2C59F614951C228D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2022-05-09 at 8.46.15 PM.png" alt="My current query" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;My current query&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Current Output&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-05-09 at 8.46.04 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19536iD6D3EAF9BA19CD8C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2022-05-09 at 8.46.04 PM.png" alt="Screen Shot 2022-05-09 at 8.46.04 PM.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Screen Shot 2022-05-09 at 8.46.04 PM.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Expected Output&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2022-05-09 at 8.52.59 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19537iEABC7E13192A2E31/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2022-05-09 at 8.52.59 PM.png" alt="Screen Shot 2022-05-09 at 8.52.59 PM.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Screen Shot 2022-05-09 at 8.52.59 PM.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 03:48:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Creating-a-table-but-it-shows-3-column-error-msg/m-p/597053#M48956</guid>
      <dc:creator>Khanu89</dc:creator>
      <dc:date>2022-05-10T03:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP error table</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Creating-a-table-but-it-shows-3-column-error-msg/m-p/597054#M48957</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244949"&gt;@Khanu89&lt;/a&gt;&amp;nbsp;- It's actually an issue with regex (rex) extracting ErrorCode, that it is extracting ErrorCode and error message everything in a single field.&lt;/P&gt;&lt;P&gt;You can try extracting them separately and then you can update your stats to add the error_msg field in the groupby (or by).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 03:16:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Creating-a-table-but-it-shows-3-column-error-msg/m-p/597054#M48957</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-05-10T03:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP error table</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Creating-a-table-but-it-shows-3-column-error-msg/m-p/597061#M48958</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/93915"&gt;@VatsalJagani&lt;/a&gt;&amp;nbsp; Thank you for your input. Can you please elaborate on how can I extract separately?&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 05:16:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Creating-a-table-but-it-shows-3-column-error-msg/m-p/597061#M48958</guid>
      <dc:creator>Khanu89</dc:creator>
      <dc:date>2022-05-10T05:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP error table</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Creating-a-table-but-it-shows-3-column-error-msg/m-p/597064#M48959</link>
      <description>&lt;LI-CODE lang="markup"&gt;| rex field=_raw "%\s(?&amp;lt;ErrorCode&amp;gt;\d+)\s(?&amp;lt;error_msg&amp;gt;.*)\s"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then you can use&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| stats ..... by ErrorCode, error_msg&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;something like this. Regex could not be valid for all the use cases, I'm just seeing a few examples from the screenshot.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2022 05:36:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Creating-a-table-but-it-shows-3-column-error-msg/m-p/597064#M48959</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-05-10T05:36:57Z</dc:date>
    </item>
  </channel>
</rss>

