I have a field called 'err_msg' this field contains a long line which consists of the error as well as the file name and other details surrounding that error. What I'm looking for is the ability to do a 'fuzzy' search in splunk on err_msg so that it will lump similar errors together. Is this possible?
Did you try the cluster search command?
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Cluster
See also:
anomalies, anomalousvalue, kmeans, outlier
It might help you.
Did you try the cluster search command?
http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Cluster
See also:
anomalies, anomalousvalue, kmeans, outlier
It might help you.
Thanks looks like cluster will do the trick!