Activity Feed
- Posted Re: Displaying 2 counts (error and total) on Splunk Search. 03-25-2020 07:16 AM
- Posted Re: Displaying 2 counts (error and total) on Splunk Search. 03-25-2020 03:39 AM
- Posted Re: Displaying 2 counts (error and total) on Splunk Search. 03-24-2020 12:21 PM
- Posted Re: Displaying 2 counts (error and total) on Splunk Search. 03-24-2020 11:44 AM
- Posted Displaying 2 counts (error and total) on Splunk Search. 03-24-2020 10:27 AM
- Tagged Displaying 2 counts (error and total) on Splunk Search. 03-24-2020 10:27 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
0 |
03-25-2020
03:39 AM
Sorry, i cant paste the logs due to security reasons.
Events are logged based on the field foundation , suppose A, B, C.
and logs will be like
index=* Foundation=A | field1 | field2| ...message......errortest.../message
index=* Foundation=A | field1 | field2| ...message......errortest.../message
index=* Foundation=B | field1 | field2| ...message......errortest.../message
index=* Foundation=C | field1 | field2| ...message......errortest.../message
here i need to segregate the events based on the error text and total count , and the output should be like
Foundation | error count | total count
A count count
B count count
C count count
and i am sorry for messing up the things.
... View more
03-24-2020
12:21 PM
field1= || field2= || field3= || message------------error text ----------/message
this is the error message structure.
here i need to separate the events which contains error text, suppose it to be errors and display both total count and error count.
... View more
03-24-2020
11:44 AM
error message has to be extracted from raw text. Then i need to display total events count and error events count.
... View more
03-24-2020
10:27 AM
There is a requirement in which i need to display total count and errors(in total count). error message is in raw text.
... View more
- Tags:
- total