Splunk Search

Question on how to use the lookup file for Exception monitoring

Deepz2612
Explorer

I have a lookup file which has below coloumns.

Exception_Name Exception_Keyword Comments
REXC RemoteException Alerted
JNEXC Exception-NullPointer Ignorable

Now in the logs when the Exception_Keyword occurs,It should look for the lookupfile and take the Exception_Name,Comments and give the result with host and count also.
And if the Exception_Keyword does not exists in lookup it should be listed as New..and when clicking on New it should show me all the new exceptions(_raw events)

Expected output as below :

Exception_Name Exception_Keyword Host count
REXC RemoteException XYZ 67
New soapexception ABC 3

Further drilling down to the New exception It should show me this list of it..Same with others also.

0 Karma

Deepz2612
Explorer

Can someone help me with this please

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...