I need a search query to find out if the replication error occurs for more than 3 times in an interval of 5 mins? I have to create a dashboard for it.
You need to define what replication error specifically means in your use case. One you do that, its quite simple, set your span for 5minutes..
yoursearch | bucket span=1m _time | stats count by host | where count > 3
This groups the events into 1 minute slices, and looks for more then 3 errors within that 5 minute window.
You can look here for specifics about different replication errors : http://docs.splunk.com/Documentation/Splunk/6.2.3/Indexer/Bucketreplicationissues
Thanks for the reply. I intend to make a dashboard on indexer replication error. Can you please refine yoursearch for this?