Splunk Search
Highlighted

By intersect, I am getting a list of hosts, but how can I use that list to get the count of errors per host?

Communicator

Hi,

By using intersect i got the list of hosts. now i want to to get the list of errors in those host. how can i achieve that .

0 Karma
Highlighted

Re: By intersect, I am getting a list of hosts, but how can I use that list to get the count of errors per host?

Motivator

Hello

You can use a subsearch to filter the main query, leike this:

YourBaseSearchToFilterErrors [search YourIntersectSearchThatReturnsAListOfHosts] | any other commands

This will transalate into something like:

index=main "error" host=1 OR host=2 OR host=3 | other commands

Regards

0 Karma
Highlighted

Re: By intersect, I am getting a list of hosts, but how can I use that list to get the count of errors per host?

Builder

Hi,

I also advice you to use a subsearch to filter the main query. this will look at this:

... [search index=name_of_your_index |stats count(error) by host]

Replace the ... by your main search

View solution in original post