Splunk Enterprise

I want to look for certain text and extract that field and make a report

mikeyty07
Explorer
index=abc "exception":"java.util.concurrent.ExecutionException" searching above displays like these in below events "exception":"java.util.concurrent.ExecutionException: ABC_1000:We're sorry, it looks like an error occurred while getting information" "exception":"java.util.concurrent.ExecutionException: ABC-2000:We're sorry, it looks like an error occurred while getting information" I want to take the ABC_ OR ABC- error codes and have a report based on that which should look like this ABC Codes message counts ABC_1000 We're sorry, it looks like an error occurred while getting information 3 ABC-2000 We're sorry, it looks like an error occurred while getting information 5
Labels (1)
0 Karma

rupkumar4sec
Path Finder
index=abc "exception":"java.util.concurrent.ExecutionException"
| rex field=_raw "Exception\:\s(?=ABC)(?<ABC_CODE>[^\:]+)\:(?<Message>[^\"]+)"
| stats count by  ABC_CODE, Message
0 Karma

mikeyty07
Explorer
index=abc "exception":"java.util.concurrent.ExecutionException" searching above displays like these in below events "exception":"java.util.concurrent.ExecutionException: ABC_1000:We're sorry, it looks like an error occurred while getting information" "exception":"java.util.concurrent.ExecutionException: ABC-2000:We're sorry, it looks like an error occurred while getting information" I want to take the ABC_ OR ABC- error codes and have a report based on that which should look like this ABC Codes message counts ABC_1000 We're sorry, it looks like an error occurred while getting information 3 ABC-2000 We're sorry, it looks like an error occurred while getting information 5
0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!