Splunk Search

Grouping by a substring

Engager

Hello,

I'm having trouble grouping errors in our Splunk logs. The date and time is appended to the error messages, meaning that every message is unique. For example:

Message=2017-06-19 09:15:23,825 ERROR - Here is the error message that we would like to group on...

I would like to ignore the date/time string and group on the text that appears after this. The best I have come up with is as follows:

Type=Error | eval ErrorString=substr(Message,30,len(Message)) | stats count by ErrorString

But this search still seems to evaluate as if the date is present in the new ErrorString string (the count is always 1 and ErrorString's are duplicated across rows)

Could you help me to write a query that would group the error messages and ignore the date/time.

Thanks,
Ross

0 Karma
1 Solution

Builder

You can extract the string at the end and use it in the grouping -

<your search> | rex field=Message "(?<ErrorString>ERROR.+)"  | stats count by ErrorString

View solution in original post

Builder

You can extract the string at the end and use it in the grouping -

<your search> | rex field=Message "(?<ErrorString>ERROR.+)"  | stats count by ErrorString

View solution in original post

Engager

Perfect, thank you!

0 Karma