Hi,
I am currently trying to find all the events that contain the phrase "ERROR" and based on their IDs, I want to see if those IDs are able to continue in the application.
Right now, I have this as my search, but it seems to only find the first error and returns that ID, only searching through that ID for the phrase "module completed":
host=... source=... [search "ERROR" | return ID] "modules completed:"
I would like the search to iterate through every ID that contains "ERROR" and look for "modules completed" within each of those IDs. Is there a way to do this?
Thanks
First of all, take a look at how subsearches work and the limitations:
https://docs.splunk.com/Documentation/Splunk/6.4.1/SearchTutorial/Useasubsearch
https://docs.splunk.com/Documentation/Splunk/6.4.1/Search/Aboutsubsearches
Having said that, give this a try:
host=... source=... "modules completed:" [search "ERROR" | table ID]
Keep in mind if you are returning thousands of IDs your search is going to be veeery slow and not great from performance point of view.
@alan20854 can you paste a sample of your events to your question above?
First of all, take a look at how subsearches work and the limitations:
https://docs.splunk.com/Documentation/Splunk/6.4.1/SearchTutorial/Useasubsearch
https://docs.splunk.com/Documentation/Splunk/6.4.1/Search/Aboutsubsearches
Having said that, give this a try:
host=... source=... "modules completed:" [search "ERROR" | table ID]
Keep in mind if you are returning thousands of IDs your search is going to be veeery slow and not great from performance point of view.
Thanks javiergn, I appreciate the help!