<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help in merging the queries in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-merging-the-queries/m-p/669183#M229523</link>
    <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=sso Appid="APP-49" PROD ("Util.validateAuth" AND "METHOD_ENTRY") OR ("RestTorHandler : hleError :" OR "java.net.SocketException: Connection reset]" OR "Error in processor call." OR level="error" NOT "resubmit the request")
| rex field=_raw " (?&amp;lt;service_name&amp;gt;\w+)-prod"
| eval err_flag = if(searchmatch("Util.validateAuth" AND "METHOD_ENTRY"), 1,0)
| eval success_flag = if(searchmatch("RestTorHandler : hleError :" OR "java.net.SocketException: Connection reset]" OR "Error in processor call." OR level="error" NOT "resubmit the request"), 1,0)
| stats sum(err_flag) as total_errors, sum(success_flag) as total_successes by service_name&lt;/LI-CODE&gt;</description>
    <pubDate>Mon, 20 Nov 2023 12:30:47 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2023-11-20T12:30:47Z</dc:date>
    <item>
      <title>Need help in merging the queries</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-merging-the-queries/m-p/669181#M229522</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i need to add two queries so that they could come in different fields in one visualization, one will be the error and one will be success transaction.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;index=sso Appid="APP-49" PROD ("Util.validateAuth" AND "METHOD_ENTRY")&amp;nbsp; &amp;nbsp;- ERROR&lt;/P&gt;&lt;P&gt;index=sso Appid="APP-49" PROD ("RestTorHandler : hleError :" OR "java.net.SocketException: Connection reset]" OR "Error in processor call." OR level="error" NOT "resubmit the request")&amp;nbsp; &amp;nbsp; &amp;nbsp; - SUCCESS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;need to add both the queries and provide the count for error and count for success but while using this query, sum of the error transaction level!=error so the error count is not matching.&lt;/P&gt;&lt;P&gt;index=ss Appid="APP-49" PROD ("Util.validateAuth" AND "METHOD_ENTRY") OR index=sso ("RestTorHandler : hleError :" OR "java.net.SocketException: Connection reset]" OR "Error in processor call." OR level="error" NOT "resubmit the request")&amp;nbsp;&lt;BR /&gt;| rex field=_raw " (?&amp;lt;service_name&amp;gt;\w+)-prod"&lt;BR /&gt;| eval err_flag = if(environment="nonprod", 1,0)&lt;BR /&gt;| eval success_flag = if(level!="ERROR", 1,0)&lt;BR /&gt;| stats sum(err_flag) as total_errors, sum(success_flag) as total_successes by service_name&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help it would be great.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 12:18:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-merging-the-queries/m-p/669181#M229522</guid>
      <dc:creator>Aj01</dc:creator>
      <dc:date>2023-11-20T12:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in merging the queries</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-merging-the-queries/m-p/669183#M229523</link>
      <description>&lt;P&gt;Try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=sso Appid="APP-49" PROD ("Util.validateAuth" AND "METHOD_ENTRY") OR ("RestTorHandler : hleError :" OR "java.net.SocketException: Connection reset]" OR "Error in processor call." OR level="error" NOT "resubmit the request")
| rex field=_raw " (?&amp;lt;service_name&amp;gt;\w+)-prod"
| eval err_flag = if(searchmatch("Util.validateAuth" AND "METHOD_ENTRY"), 1,0)
| eval success_flag = if(searchmatch("RestTorHandler : hleError :" OR "java.net.SocketException: Connection reset]" OR "Error in processor call." OR level="error" NOT "resubmit the request"), 1,0)
| stats sum(err_flag) as total_errors, sum(success_flag) as total_successes by service_name&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 20 Nov 2023 12:30:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-merging-the-queries/m-p/669183#M229523</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-20T12:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in merging the queries</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-merging-the-queries/m-p/669322#M229565</link>
      <description>&lt;P&gt;It is not working as if doesn't take AND and NOT in if command.&lt;/P&gt;&lt;P&gt;getting error :&amp;nbsp;&lt;SPAN&gt;Error in 'EvalCommand': The expression is malformed. Expected ).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 12:57:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-merging-the-queries/m-p/669322#M229565</guid>
      <dc:creator>Aj01</dc:creator>
      <dc:date>2023-11-21T12:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in merging the queries</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Need-help-in-merging-the-queries/m-p/669326#M229567</link>
      <description>&lt;P&gt;No, it's about the unescaped quotes in the searchmatch() argument. If it needs embedded strings, the quotes for those strings should be escaped.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 13:30:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Need-help-in-merging-the-queries/m-p/669326#M229567</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-21T13:30:45Z</dc:date>
    </item>
  </channel>
</rss>

