Splunk Search

most common events

tlow
Explorer

Hello, in my search how do i find most common events.

tried this | cluster | table cluster_count, _raw | sort - cluster_count
but not displaying the cluster_count.

need to find what errors are generated the most.
Thanks

0 Karma

lguinn2
Legend

The problem as I see it: you need to decide how to group the events. You can try cluster but it better if you define "common".

Here is one possible search:

error* | stats count by source sourcetype host | sort -count

This will give you a count of the events that contain the word "error", with the most common host source and sourcetype listed first in the list.

Here is another - this also groups the errors by including a few of the characters that surround the word "error"

error* | rex "(?<msg>.{0,25}error.{0,25})"  | stats count by source sourcetype host msg | sort -count
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...