Hi ,
I have set up alerting on Java exceptions:
My search string:
index=myapp_logs source=/opt/man/myapp/myapp.log exception=java*
The above search emails us when a threshold for no of exceptions is met.
I need Spunk to exclude some specific exceptions, Spunk should ignore these multiple exceptions.
java.test.IllegArgumentException
java.test.IllegArgumentException
javat.persistence.testException
How do i get this done?
Can you not try to modify the initial search to exclude the strings that you do not require as a start, something like:
index=myapp_logs source=/opt/man/myapp/myapp.log exception=java* NOT ( exception=java*IllegArgumentException OR exception=javat.persistence.testException)
OR if you do some multivalued extractions from where these exception strings are extracted then close the SPL with | search exception!=java*IllegArgumentException
and so on.
Can you not try to modify the initial search to exclude the strings that you do not require as a start, something like:
index=myapp_logs source=/opt/man/myapp/myapp.log exception=java* NOT ( exception=java*IllegArgumentException OR exception=javat.persistence.testException)
OR if you do some multivalued extractions from where these exception strings are extracted then close the SPL with | search exception!=java*IllegArgumentException
and so on.
Thanks ! this works.