Hi,
I've three different types of logs.
Sharepoint:
04/14/2013 23:51:56.49 wsstracing.exe (0x0B14) 0x1874 SharePoint Foundation Unified Logging Service b9wt High Log retention limit reached. Log file 'C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\LOGS\LNTVANEBPSP-20130404-2321.log' has been deleted.
04/14/2013 23:51:56.49 wsstracing.exe (0x0B14) 0x1874 SharePoint Foundation Tracing Controller Service 8096 Information Usage log retention limit reached. Some old usage log files have been deleted.
Event logs :
04/30/2013 04:38:43 PM
LogName=Application
SourceName=MSCRMTracing
EventCode=17203
EventType=2
Type=Error
ComputerName=LnTVanEBPCRM.LnTVan.com
TaskCategory=None
OpCode=None
RecordNumber=24797628
Keywords=Classic
Message=Splunk could not get the description for this event. Either the component that raises this event is not installed on your local computer or the installation is corrupt.
database log :
2013-04-05 19:29:17.25 spid31s Starting up database 'msdb'.
2013-04-05 19:29:17.25 spid32s Starting up database 'ReportServer'.
2013-04-05 19:29:19.47 Logon Error: 17187, Severity: 16, State: 1.
2013-04-05 19:29:19.47 Logon SQL Server is not ready to accept new client connections. Wait a few minutes before trying again. If you have access to the error log, look for the informational message that indicates that SQL Server is ready before trying to connect again. [CLIENT: 192.168.33.61]
2013-04-05 19:29:19.47 Logon Error: 17187, Severity: 16, State: 1.
2013-04-05 19:29:19.47 Logon SQL Server is not ready to accept new client connections. Wait a few minutes before trying again. If you have access to the error log, look for the informational message that indicates that SQL Server is ready before trying to connect again. [CLIENT: 192.168.33.61]
2013-04-05 19:29:22.21 Logon Error: 17187, Severity: 16, State: 1.
Currently I've done some searches in these 3 and shown charts in 3 different dashboards.
Now the question is, can we show the result of all these different searches in a single chart?
For example
single chart showing errors in sharepoint logs, database logs, event logs.?
Is this possible to do?
Yes, it can be done in a single chart:
(sourcetype=sharepoint "error") OR (sourcetype=database "error") OR (sourcetype=eventlog "error")
| stats count by sourcetype
or
(sourcetype=sharepoint "error") OR (sourcetype=database "error") OR (sourcetype=eventlog "error")
| timechart count by sourcetype
Note that I have combined three very simple searches, but you can substitute your actual three searches into the command instead. If this isn't helpful, perhaps you can share the three searches that you are using now.
Yes, it can be done in a single chart:
(sourcetype=sharepoint "error") OR (sourcetype=database "error") OR (sourcetype=eventlog "error")
| stats count by sourcetype
or
(sourcetype=sharepoint "error") OR (sourcetype=database "error") OR (sourcetype=eventlog "error")
| timechart count by sourcetype
Note that I have combined three very simple searches, but you can substitute your actual three searches into the command instead. If this isn't helpful, perhaps you can share the three searches that you are using now.
Thanks a lot. It worked :).
Do you want them it to be in single panel / single dashboard page?