Splunk Search

Condition and Search string together not working

satyajit2007
Explorer

 

In Total_error Count , I want to add if the logs contains string like "exception", "failed", "error" ( Case Insensitive if possible ).  in addition to level=ERROR condition. 

 

 

index=myIndex sourcetype=mySourceType | 
timechart count as total_logs count(eval(level="INFO")) as total_info count(eval(level="WARN")) as total_warn count(eval(level="ERROR")  ) as total_error span=1h

 

 

 

Added those search criteria like this . did not work . 

count(eval(level="ERROR" OR ("Failed" OR "Exception" OR "Fatal")  )

 

The condition should be 

where level="ERROR" OR ( log like '%failed%' or log like '%Exception%')    ( case should not matter). 

Need your expert advise.

Labels (4)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

I replied to your previous message on this topic.  https://community.splunk.com/t5/Splunk-Search/Search-strings-and-conditions-together/m-p/529223/high...

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Automatic Discovery Part 2: Setup and Best Practices

In Part 1 of this series, we covered what Automatic Discovery is and why it’s critical for observability at ...