Assuming you have the err_cd field extracted, you just need to top
command. Try something like this
your base search here | top err_cd | fields - count
This will give you top 10 err_cd, count and percent. The fields - count
command will remove the count
field from display.
http://docs.splunk.com/Documentation/Splunk/6.4.1/SearchReference/Top
HI Sundaresh.
Thanks for the update.
I am searching for error codes from log files in an environment.
How could I separate out only error code from the logs .
I mean error codes can be like err20 or err31 , just an example.
And also could you suggest on how I can use error code as field in top command.