Splunk Search

Question on how to use the lookup file for Exception monitoring


I have a lookup file which has below coloumns.

Exception_Name Exception_Keyword Comments
REXC RemoteException Alerted
JNEXC Exception-NullPointer Ignorable

Now in the logs when the Exception_Keyword occurs,It should look for the lookupfile and take the Exception_Name,Comments and give the result with host and count also.
And if the Exception_Keyword does not exists in lookup it should be listed as New..and when clicking on New it should show me all the new exceptions(_raw events)

Expected output as below :

Exception_Name Exception_Keyword Host count
REXC RemoteException XYZ 67
New soapexception ABC 3

Further drilling down to the New exception It should show me this list of it..Same with others also.

0 Karma


Can someone help me with this please

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...