I am novice to splunk and need help in writing a splunk query in order to find Order ID (ORD********)
I can't see your sample data.
run in bar search the following search:
index=your_index_name source=your_source_name sourcetype=your_sourcetype_name
index=your_index_name source=your_source_name sourcetype=your_sourcetype_name|....your_condictions_search
index=you_index host=you_host "Error" | chart count sparkline(count, 1h) as trend by host | sort -count
Is this even related to the question?