I have created a lookup file(.csv) file with known exception. My question is how to create a search that can look against that known exceptions.
I want to get results only when a different exception appear(exception that never happened before), also i want to make an alert.
When i tried to make an search to look against that file the results will also shows exceptions that are in .csv file.
How can i do this? Is there another better option?
My .csv file look like this(140 exceptions), also my environment :
If you've your "exception" field extracted already, try something like this
index=yourIndex sourcetype=yourSourcetype NOT [| inputlookup yourExceptionLookup.csv | table exception ]
If field is not already extracted, consider doing so and use above query.
If field extraction is not possible, and you want to do a less efficient text search, try something like this
index=yourIndex sourcetype=yourSourcetype NOT [| inputlookup yourExceptionLookup.csv | table exception | rename exception as search ]
Could you help me?
Stll not very clear to me.
index=doc1 sourcetype=at-doc1 NOT [| inputlookup yourExceptionLookup.csv | table exception ]
Let say i have the index doc1, and sourcetype=at-doc1. If i perform this search will extract all the events, even what i have in the file(if the log is different but include the exception name). I expect to get some exception that are not in the .csv. I'm doing something wrong?
Somehow i want to get the type of exceptions that never happened before and fully exclude the exceptions i know from file. Is that possible?
As you can see my environment(logs) are different everytime i dont know if this is the cause but even if they are different i want to exclude entire log if this is contain something from the .csv