Getting Data In

How do I make a Splunk query that reads all error code , it's message and count?

gauravepi
Path Finder

I have a JSON response now, and, from that, i want to create a table that will have all Unique Error Codes, Messages and Count . I am not able to read the JSON message in Splunk. How can we do this in Splunk? Below is one sample JSON response which i have

level:   DEBUG  
line:    43 
logger:  ErrorUtils 
message: Error: {"ErrorCode":"201","Message":"Invalid User"}    

I have created a query just to read the eventtype. i am not sure how i can proceed further on this.

eventtype="myevent"
Tags (2)
0 Karma

pramit46
Contributor

Assuming your json is properly formatted, try setting KV_Mode=json in your props.conf file against that sourcetype. It should automatically extract the field values from the json events.

You can read more about it here:
https://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf

Let me know if that helps.

0 Karma

Rob2520
Communicator

Can you share your whole JSON event?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...