Splunk Search

i want to create the field of error :

Joycetran
New Member

alt text

create the field "DM Call errors #" ,
then count this number.
I tried to use case, but I dont have the field as title to match

Tags (1)
0 Karma

jpolvino
Builder

If you're trying to create a new field for the DM Call Errors that contains the count for each event, then this is one way to do it:

(your search here) | rex "DM Call  errors #  : (?<DmCallErrors>\d+)"

Then you can add then up the field values using

| stats count(DmCallErrors) AS "Count of DM Call Errors"

somewhere after the extract.

If you and others need this, talk to your Splunk admin about having this field created when the log gets ingested, so you won't have to worry about the rex.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...