<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Grouping (Range?) HTTP Status codes in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Grouping-Range-HTTP-Status-codes/m-p/342481#M161304</link>
    <description>&lt;P&gt;Wow, tat is pretty good!  It doesn't seem to get the 500-599 ones though.  &lt;/P&gt;</description>
    <pubDate>Thu, 20 Apr 2017 19:05:58 GMT</pubDate>
    <dc:creator>dbcase</dc:creator>
    <dc:date>2017-04-20T19:05:58Z</dc:date>
    <item>
      <title>Grouping (Range?) HTTP Status codes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Grouping-Range-HTTP-Status-codes/m-p/342479#M161302</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have queries that I'd like to group HTTP Status codes together...  (i.e.  anything 200-299, or 300-399, or 400-499, or 500-599) . I have a dropdown that prompts the user to select&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; &amp;lt;input type="dropdown" token="http_code" searchWhenChanged="true"&amp;gt;
        &amp;lt;label&amp;gt;Select Http Status Code Range:&amp;lt;/label&amp;gt;
        &amp;lt;default&amp;gt;200&amp;lt;/default&amp;gt;
        &amp;lt;choice value="200"&amp;gt;200 - 299&amp;lt;/choice&amp;gt;
        &amp;lt;choice value="300"&amp;gt;300 - 399&amp;lt;/choice&amp;gt;
        &amp;lt;choice value="400"&amp;gt;400 - 499&amp;lt;/choice&amp;gt;
        &amp;lt;choice value="500"&amp;gt;500 - 599&amp;lt;/choice&amp;gt;

      &amp;lt;/input&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;but I'm not sure how to get the query working.  This is what I have it it kinda works but it still returns other codes even thought the value is zero&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=itscom source=*access* |rex "HTTP\S+ (?&amp;lt;status&amp;gt;\d+)"|stats count(eval(searchmatch("status=2*"))) as "200-299" by status
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2815iD749E32A142485B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 18:26:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Grouping-Range-HTTP-Status-codes/m-p/342479#M161302</guid>
      <dc:creator>dbcase</dc:creator>
      <dc:date>2017-04-20T18:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Grouping (Range?) HTTP Status codes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Grouping-Range-HTTP-Status-codes/m-p/342480#M161303</link>
      <description>&lt;P&gt;Try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=itscom source=*access* |rex "HTTP\S+ (?&amp;lt;status&amp;gt;\d+)" 
| bucket status span=100 | eval status=mvindex(split(status,"-"),0)."-".(tonumber(mvindex(split(status,"-"),1))-1)
| stats count by status
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 20 Apr 2017 18:56:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Grouping-Range-HTTP-Status-codes/m-p/342480#M161303</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-04-20T18:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: Grouping (Range?) HTTP Status codes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Grouping-Range-HTTP-Status-codes/m-p/342481#M161304</link>
      <description>&lt;P&gt;Wow, tat is pretty good!  It doesn't seem to get the 500-599 ones though.  &lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 19:05:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Grouping-Range-HTTP-Status-codes/m-p/342481#M161304</guid>
      <dc:creator>dbcase</dc:creator>
      <dc:date>2017-04-20T19:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Grouping (Range?) HTTP Status codes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Grouping-Range-HTTP-Status-codes/m-p/342482#M161305</link>
      <description>&lt;P&gt;Lets try this than&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=itscom source=*access* |rex "HTTP\S+ (?\d+)" 
 | bucket status span=100 | eval status=mvindex(split(status,"-"),0)."-".(tonumber(mvindex(split(status,"-"),0))+99)
 | stats count by status
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 20 Apr 2017 19:08:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Grouping-Range-HTTP-Status-codes/m-p/342482#M161305</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-04-20T19:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Grouping (Range?) HTTP Status codes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Grouping-Range-HTTP-Status-codes/m-p/342483#M161306</link>
      <description>&lt;P&gt;nevermind, my fat fingers can't type so well &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2017 19:09:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Grouping-Range-HTTP-Status-codes/m-p/342483#M161306</guid>
      <dc:creator>dbcase</dc:creator>
      <dc:date>2017-04-20T19:09:25Z</dc:date>
    </item>
  </channel>
</rss>

