Splunk Search

query on splunk for new error(exeption on server)

sagineshmk
New Member

Hi,

Requires a query that search for non-repetitive error/exception on server ie it will show only new error that has not occured more than 30 days.

Regards,
SAGINESH

Tags (1)
0 Karma

jhupka
Path Finder

There's a lot of different ways to approach this - are you planning on creating an alert from a scheduled search running every 15m? Do you want to just create a dashboard with uncommon or recent errors? What do you want to tell the consumer of the search result about the error - what host it came from? The error itself? Any other info?

For now we can choose a simple case. Let's assume your data's sourcetype is sagineshmk_logs, and the error is in a field named error_name. You could do a search like the following:

sourcetype=sagineshmk_logs earliest=-30d@d | stats count as error_count, max(_time) as _time by error_name | where error_count=1

For a production environment, though, I might not want to run the above search every 15m and constantly look over 30 days of data. In that case I may split the search into two separate pieces - one search to compile a list of unique errors in the last 30 days (e.g. run that daily), then a second search that only looks at the past 15 minute's worth of errors and compares it to my daily unique error list.

sloshburch
Splunk Employee
Splunk Employee

@sagineshmk, did this answer your question? If so, you can "accept" this or provide clarifying information to continue the discussion.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...