Splunk Search

query on splunk for new error(exeption on server)

sagineshmk
New Member

Hi,

Requires a query that search for non-repetitive error/exception on server ie it will show only new error that has not occured more than 30 days.

Regards,
SAGINESH

Tags (1)
0 Karma

jhupka
Path Finder

There's a lot of different ways to approach this - are you planning on creating an alert from a scheduled search running every 15m? Do you want to just create a dashboard with uncommon or recent errors? What do you want to tell the consumer of the search result about the error - what host it came from? The error itself? Any other info?

For now we can choose a simple case. Let's assume your data's sourcetype is sagineshmk_logs, and the error is in a field named error_name. You could do a search like the following:

sourcetype=sagineshmk_logs earliest=-30d@d | stats count as error_count, max(_time) as _time by error_name | where error_count=1

For a production environment, though, I might not want to run the above search every 15m and constantly look over 30 days of data. In that case I may split the search into two separate pieces - one search to compile a list of unique errors in the last 30 days (e.g. run that daily), then a second search that only looks at the past 15 minute's worth of errors and compares it to my daily unique error list.

sloshburch
Ultra Champion

@sagineshmk, did this answer your question? If so, you can "accept" this or provide clarifying information to continue the discussion.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...