Splunk Search
Highlighted

Fuzzy Search

Communicator

I have a field called 'errmsg' this field contains a long line which consists of the error as well as the file name and other details surrounding that error. What I'm looking for is the ability to do a 'fuzzy' search in splunk on errmsg so that it will lump similar errors together. Is this possible?

Tags (1)
0 Karma
Highlighted

Re: Fuzzy Search

Motivator

Did you try the cluster search command?

http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Cluster

See also:

anomalies, anomalousvalue, kmeans, outlier

It might help you.

View solution in original post

Highlighted

Re: Fuzzy Search

Communicator

Thanks looks like cluster will do the trick!

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.