Splunk Search

How to find common errors in different log files?

Reddi694325
Path Finder

In my environment I got one scenario like have to find common errors in iis log, applog,apache log and db log. How to find it

Please help me on the same

Thanks in Advance

0 Karma

nickhills
Ultra Champion

Hi @Reddi694325
Many log types have a 'level' which is normally one of INFO/WARN/ERROR etc.
Some logs report a status code which indicates the outcome.

If you have installed the appropriate TA for your log type this should be extracted for you You need to identify those fields/tags/values and write a search to identify them.

(sourcetype=iis AND sc_status>=400) OR (sourcetype=myApp AND log_level=error)
If my comment helps, please give it a thumbs up!
0 Karma

richgalloway
SplunkTrust
SplunkTrust

What qualifies as a "common error" in three very different logs?

---
If this reply helps you, Karma would be appreciated.
0 Karma

Reddi694325
Path Finder

Actually I am thinking is there any way to find by using codes like 404,500.............

three are different logs I know But code doesn't change I think.

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...