Splunk Search

Counting how many unique id #s have only INFO logs (rather than Error logs)

muhan421
Loves-to-Learn Lots

I'm trying work with a bunch of system logs that are either ERROR or INFO logs. Each has a unique id # that is specific to a certain package.

I'm trying to figure out a way to count how my these unique id #s are only present in INFO logs meaning that there was no issues associated with that id #. 

There are multiple logs associated with each ID# so if that id# is in 5 INFO logs but 1 ERROR logs, it shouldn't be counted. But if it's in only 1 INFO log, that should be counted.

I'm novice with Splunk and I need to figure this out for my internship ASAP so all help is appreciated. 

Thanks!

 

 

 

Labels (3)
Tags (3)
0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...