<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to sum status like 201, 202 error status become 2xx.? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-sum-status-like-201-202-error-status-become-2xx/m-p/622777#M216512</link>
    <description>&lt;P&gt;I want to get a search for get sum status error of http_user_agent like second dashboard. I do not know how to sum status like 201, 202 error status becom 2xx. &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2022-12-01 at 15.45.40.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22747iD6E47FF162AD640F/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2022-12-01 at 15.45.40.jpg" alt="WhatsApp Image 2022-12-01 at 15.45.40.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2022-12-01 at 15.45.09.jpg" style="width: 765px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22746i7B24EFD11A2A3C5E/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2022-12-01 at 15.45.09.jpg" alt="WhatsApp Image 2022-12-01 at 15.45.09.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Dec 2022 16:46:23 GMT</pubDate>
    <dc:creator>Chaser</dc:creator>
    <dc:date>2022-12-01T16:46:23Z</dc:date>
    <item>
      <title>How to sum status like 201, 202 error status become 2xx.?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-sum-status-like-201-202-error-status-become-2xx/m-p/622777#M216512</link>
      <description>&lt;P&gt;I want to get a search for get sum status error of http_user_agent like second dashboard. I do not know how to sum status like 201, 202 error status becom 2xx. &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2022-12-01 at 15.45.40.jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22747iD6E47FF162AD640F/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2022-12-01 at 15.45.40.jpg" alt="WhatsApp Image 2022-12-01 at 15.45.40.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2022-12-01 at 15.45.09.jpg" style="width: 765px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22746i7B24EFD11A2A3C5E/image-size/large?v=v2&amp;amp;px=999" role="button" title="WhatsApp Image 2022-12-01 at 15.45.09.jpg" alt="WhatsApp Image 2022-12-01 at 15.45.09.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 16:46:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-sum-status-like-201-202-error-status-become-2xx/m-p/622777#M216512</guid>
      <dc:creator>Chaser</dc:creator>
      <dc:date>2022-12-01T16:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Error Status</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-sum-status-like-201-202-error-status-become-2xx/m-p/622780#M216515</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251686"&gt;@Chaser&lt;/a&gt;When you ask a question, please illustrate data in text. You can add screenshots if that's helpful, but do not solely rely on screenshot. In this case, I don't see how the first screenshot is useful in explaining your question. It doesn't contain anything related to status error, just a list of &lt;SPAN&gt;http_user_agent values. Is status error already extracted as a separate field?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Assuming that status error &lt;STRONG&gt;is &lt;/STRONG&gt;already in a field, say, http_status_error, it is still unclear what you mean by "sum status error". You example about "2xx" makes me speculate that all you want is to count by the first digit of status error and chart over user agent. (Try not to make others read your mind.) If so, try&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| eval http_status_error = replace(http_status_error, "\d\d$", "")
| chart count over http_user_agent by http_status_error&lt;/LI-CODE&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 09:51:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-sum-status-like-201-202-error-status-become-2xx/m-p/622780#M216515</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2022-12-01T09:51:39Z</dc:date>
    </item>
  </channel>
</rss>

