Splunk Search

Condition and Search string together not working

satyajit2007
Explorer

 

In Total_error Count , I want to add if the logs contains string like "exception", "failed", "error" ( Case Insensitive if possible ).  in addition to level=ERROR condition. 

 

 

index=myIndex sourcetype=mySourceType | 
timechart count as total_logs count(eval(level="INFO")) as total_info count(eval(level="WARN")) as total_warn count(eval(level="ERROR")  ) as total_error span=1h

 

 

 

Added those search criteria like this . did not work . 

count(eval(level="ERROR" OR ("Failed" OR "Exception" OR "Fatal")  )

 

The condition should be 

where level="ERROR" OR ( log like '%failed%' or log like '%Exception%')    ( case should not matter). 

Need your expert advise.

Labels (4)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I replied to your previous message on this topic.  https://community.splunk.com/t5/Splunk-Search/Search-strings-and-conditions-together/m-p/529223/high...

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...