Splunk Search

Tabulate list of exception in logs

thaara
Explorer

Hi Splunkers,

My logs are like below with same set of logs for different WAS ear's..

earFile=abc.ear
...................................
Error1: Exception with DMGR.....
Dbjbafjbjasbfbuasbhcbjsa

earFile=qrs.ear
...................................
Error2: SOAP exception..
skbdjasbjdgajsgdgush

My query should seach 'Error1' and 'Error2' keyword. In result, it should shows whole error message..

For eg,

If i search 'Error1' & 'Error2' in my query, output should be like below in table format...

Host EAR_Name Error
xyz abc.ear Error1: Exception with DMGR.....
Dbjbafjbjasbfbuasbhcbjsa

xyz qrs.ear Error2: SOAP exception..
skbdjasbjdgajsgdgush

0 Karma

dindu
Contributor

Could you please try the below.

   |index="your_index" sourcetype="" Error1 Error2
   |rex field=_raw "(?P<err_message>Error.*)"
    |table host,earFile,err_message
0 Karma

richgalloway
SplunkTrust
SplunkTrust

What is your current query? What are your current results?

---
If this reply helps you, Karma would be appreciated.
0 Karma

thaara
Explorer

Current query:
index= " " sorucetype= " " Error

Result:
we are getting all the error patterns, but not in tabular format.

Expected output:
Hostname ear.name type of exception
xyz xyz.ear DMGR exception
abc abc.ear SOAP exception

0 Karma

richgalloway
SplunkTrust
SplunkTrust

As @dindu's answer suggests, you can use the table command to put your results in tabular form.
See https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

What’s new on Splunk Lantern in August

This month’s Splunk Lantern update gives you the low-down on all of the articles we’ve published over the past ...

Welcome to the Future of Data Search & Exploration

You have more data coming at you than ever before. Over the next five years, the total amount of digital data ...

This Week's Community Digest - Splunk Community Happenings [8.3.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...