Splunk Search

Display field uniques in search

aaronnicoli
Path Finder

Hi there,

What I am after is quite straight forward really. I am trying to conduct a search of a particular index (prod_apache) and display any "File does not exist" errors.

This is very easy to accomplish (obviously)... however, I don't want to display the same file over and over again and would just like to display a list of which files don't exist.

Being that this seems like quite a straight forward thing to do (at least in my eyes) I was wondering if anyone knows how I would go about doing it.

Thanks, Aaron.

Tags (2)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee
index=prod_apache "File does not exist" | dedup file_name

Assuming you've got file_name extracted as a field containing the file name. Or:

index=prod_apache "File does not exist" | stats count by file_name

for a count of how many errors per file.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee
index=prod_apache "File does not exist" | dedup file_name

Assuming you've got file_name extracted as a field containing the file name. Or:

index=prod_apache "File does not exist" | stats count by file_name

for a count of how many errors per file.

aaronnicoli
Path Finder

Thanks again for your help.
After I configured the extraction, it worked perfectly.

0 Karma
Get Updates on the Splunk Community!

Platform Newsletter Highlights | March 2023

 March 2023 | Check out the latest and greatestIntroducing Splunk Edge Processor, simplified data ...

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...