<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why am I receiving specific error message from the raw output? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-receiving-specific-error-message-from-the-raw-output/m-p/636564#M221074</link>
    <description>&lt;P&gt;I am using the below cluster search&amp;nbsp;&lt;/P&gt;
&lt;P&gt;| cluster t=0.1 showcount=t countfield=no_of_events | table _time,no_of_events _raw | sort -no_of_events | dedup no_of_events&lt;/P&gt;
&lt;P&gt;in the output iam getting the entire raw message as in the table. however, i want to show only the error message.&lt;/P&gt;
&lt;P&gt;Is there any way to extract only specific messages instead of full raw message&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2023 07:35:31 GMT</pubDate>
    <dc:creator>Sudharsanan27</dc:creator>
    <dc:date>2023-03-30T07:35:31Z</dc:date>
    <item>
      <title>Why am I receiving specific error message from the raw output?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-receiving-specific-error-message-from-the-raw-output/m-p/636564#M221074</link>
      <description>&lt;P&gt;I am using the below cluster search&amp;nbsp;&lt;/P&gt;
&lt;P&gt;| cluster t=0.1 showcount=t countfield=no_of_events | table _time,no_of_events _raw | sort -no_of_events | dedup no_of_events&lt;/P&gt;
&lt;P&gt;in the output iam getting the entire raw message as in the table. however, i want to show only the error message.&lt;/P&gt;
&lt;P&gt;Is there any way to extract only specific messages instead of full raw message&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 07:35:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-receiving-specific-error-message-from-the-raw-output/m-p/636564#M221074</guid>
      <dc:creator>Sudharsanan27</dc:creator>
      <dc:date>2023-03-30T07:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: Get the specific error message from the Raw output.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-am-I-receiving-specific-error-message-from-the-raw-output/m-p/636567#M221076</link>
      <description>&lt;P&gt;That very much depends on the difference between raw message and the error message you are looking for. &amp;nbsp;The whole point of Splunk in my view is the freedom to extract any token into data field. &amp;nbsp;But you have to show what raw message contains and which part you consider an error message. (Anonymize as needed.)&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2023 18:27:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-am-I-receiving-specific-error-message-from-the-raw-output/m-p/636567#M221076</guid>
      <dc:creator>yuanliu</dc:creator>
      <dc:date>2023-03-29T18:27:25Z</dc:date>
    </item>
  </channel>
</rss>

