Splunk Search

Question on how to use the lookup file for Exception monitoring

Deepz2612
Explorer

I have a lookup file which has below coloumns.

Exception_Name Exception_Keyword Comments
REXC RemoteException Alerted
JNEXC Exception-NullPointer Ignorable

Now in the logs when the Exception_Keyword occurs,It should look for the lookupfile and take the Exception_Name,Comments and give the result with host and count also.
And if the Exception_Keyword does not exists in lookup it should be listed as New..and when clicking on New it should show me all the new exceptions(_raw events)

Expected output as below :

Exception_Name Exception_Keyword Host count
REXC RemoteException XYZ 67
New soapexception ABC 3

Further drilling down to the New exception It should show me this list of it..Same with others also.

0 Karma

Deepz2612
Explorer

Can someone help me with this please

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...