How do I add meaningful labels to error codes?
index=akamai_pi_prod message.reqHost=*rpama* message.status IN ("200","201","204","206","302","304","403","404","500","502")|rename message.status="200" as "200-Success"| chart count by message.reqHost,message.status
message.reqHost 200 206 304 502
message.reqHost 200-Succes 206 -Partial Content 304-Cache 502-Bad Gateway
Appreciate your help on this
Thanks,
Harish
Eval is your friend. Try this:
index=akamai_pi_prod message.reqHost=rpama message.status IN ("200","201","204","206","302","304","403","404","500","502") | eval Status=case(message.status == 200, "Success", message.status == 206, "Partial Content", message.status == 304, "Cache", message.status == 502, "Bad Gateway", true(), "Unknown") | stats count by message.reqHost,Status
Current Query :
index=akamai_pi_prod message.reqHost=rpama message.status IN ("200","201","204","206","302","304","403","404","500","502")|chart count by message.reqHost,message.status
You can do in Settings->fields->CalculatedFields
No, I dont have access to Splunk configurations so I have to manage with Splunk query only
Do the rename for each status code after the chart command-
chart count by message.reqHost,message.status| rename "200" as "Success_200", 206 as "206-Partial" ....