Splunk Search

How to generate a search to find errors by type for my error log?

kirankotla
New Member
ERROR - *(somedata).
 FlatFile ERROR - 2649 BUSINESS_LOGIC 
 ERROR - More than 1 primary id found for the given offering  

i wants to find errors type by some data

0 Karma

somesoni2
Revered Legend

Try like this

your base search (e.g. index=foo sourcetype=bar "ERROR") 
| rex "ERROR - (?<Error_Message>.+)" 
| stats count by Error_Message

kirankotla
New Member

Hi
All logs are bellow format ,i wants to chart over unique errors ,and count of each error.
ERROR - More than 1 primary id found for
ERROR - 75785 BUSINESS_LOGIC The number
ERROR - something

0 Karma

somesoni2
Revered Legend

Could you provide more information on your requirement here? You want to just filter the events which has error in formation ERROR - <<errormessage>> ?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...