Splunk Search

Need a help with Query

SR
Observer

Below was the question for me
"I need a running report to be exported, with the number of errors on each of the services in the last 7 days then it has to show a graph for each week"

i would need a query to search for this Serivce "Per****ng.N**s.Platform.Host"
Index="Nex"
where i would need data for Information, Error, Debug, Warnings.

Please help me with this 

Labels (4)
0 Karma

SR
Observer

Apologies i am pretty New to Splunk  and i still learning and going through tutorials
just got till the below but no results yet 

Index="Nex" Application="Pe***g.Ne**s.Platform.Host"| Search 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @SR .. may i know if you get results for the first search.. if no, pls understand that Application= may be service= or something else(depends on your logs). 

if your search fails, then pls check the search below:

do you get results for 
index="Nex" Application="Pe***g.Ne**s.Platform.Host"

OR the better do this search
index="Nex" "Pe***g.Ne**s.Platform.Host"

maybe pls send me a direct msg here in my profile, i can try to help you further. thanks.  

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Asterisks are wild cards - are you really using wildcards or are you just obfuscating your search for the purposes of posting here?

It would also be very helpful if you could share some sample raw events, anonymised appropriately; please share them in a code block using the </> button to create an area to place them in so that formatting is preserved

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What have you tried so far?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...