Hi,
I am looking for a query to get list of DBConnect exceptions with their timestamp in order to plot them in a graph.
Thank you
Kind regards
Marta
What events do you have ingested into Splunk showing this condition?
Splunk is logging something in the index=_internal. For instance if I run "index=_internal dbconnect" I see something but I am not sure that this is the exact query.
Are the events you are interested in returned by this search?
Do you need to filter further e.g.
index=_internal dbconnect exception
Actually the event I am interest in are not returned by this search. I noticed that this search is returning as event the query that I am doing. Maybe I should search a different index.