Splunk Search

How to display multiple search values as search coumns in the search table

kodali21055
New Member

Hi,

My application has lot of error codes(all most 35) which logs in the log file. I want to get count of each error code from the log file. For that I have written the rex as
rex "(?\d+)" | chart count by DIID, cbs2_error_code
Which is giving the out put till only 10 error codes and rest of them comes under OTHER

For eg:
20009 21002 21003 21999 25002 25017 25100 25107 25111 25113 OTHER
20 35 5 8 10 14 20 12 11 10 40

But I have lot of other error codes like 10001, 10002, 10003,.. which all are come under OTHER

Can some one help me how best I can get the report with count of each error code in the log file?

Thanks In Advance

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...