Splunk Search

How to display multiple search values as search coumns in the search table

kodali21055
New Member

Hi,

My application has lot of error codes(all most 35) which logs in the log file. I want to get count of each error code from the log file. For that I have written the rex as
rex "(?\d+)" | chart count by DIID, cbs2_error_code
Which is giving the out put till only 10 error codes and rest of them comes under OTHER

For eg:
20009 21002 21003 21999 25002 25017 25100 25107 25111 25113 OTHER
20 35 5 8 10 14 20 12 11 10 40

But I have lot of other error codes like 10001, 10002, 10003,.. which all are come under OTHER

Can some one help me how best I can get the report with count of each error code in the log file?

Thanks In Advance

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...