Splunk Search

How to display multiple search values as search coumns in the search table

kodali21055
New Member

Hi,

My application has lot of error codes(all most 35) which logs in the log file. I want to get count of each error code from the log file. For that I have written the rex as
rex "(?\d+)" | chart count by DIID, cbs2_error_code
Which is giving the out put till only 10 error codes and rest of them comes under OTHER

For eg:
20009 21002 21003 21999 25002 25017 25100 25107 25111 25113 OTHER
20 35 5 8 10 14 20 12 11 10 40

But I have lot of other error codes like 10001, 10002, 10003,.. which all are come under OTHER

Can some one help me how best I can get the report with count of each error code in the log file?

Thanks In Advance

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...