Splunk Search

Need a help with Query

SR
Observer

Below was the question for me
"I need a running report to be exported, with the number of errors on each of the services in the last 7 days then it has to show a graph for each week"

i would need a query to search for this Serivce "Per****ng.N**s.Platform.Host"
Index="Nex"
where i would need data for Information, Error, Debug, Warnings.

Please help me with this 

Labels (4)
0 Karma

SR
Observer

Apologies i am pretty New to Splunk  and i still learning and going through tutorials
just got till the below but no results yet 

Index="Nex" Application="Pe***g.Ne**s.Platform.Host"| Search 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @SR .. may i know if you get results for the first search.. if no, pls understand that Application= may be service= or something else(depends on your logs). 

if your search fails, then pls check the search below:

do you get results for 
index="Nex" Application="Pe***g.Ne**s.Platform.Host"

OR the better do this search
index="Nex" "Pe***g.Ne**s.Platform.Host"

maybe pls send me a direct msg here in my profile, i can try to help you further. thanks.  

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Asterisks are wild cards - are you really using wildcards or are you just obfuscating your search for the purposes of posting here?

It would also be very helpful if you could share some sample raw events, anonymised appropriately; please share them in a code block using the </> button to create an area to place them in so that formatting is preserved

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What have you tried so far?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...