Hi,
I am a new user to splunk.
Our splunk data consists of lines like:
engine id=
engine id=
engine id=
engine id=
I would like to be able to get histogram of how many errors of each types where found, without mention errors implicitly and ignoring id field.
(error1:1, error3:2, error2:1 in this case)
How can I do it ?
Thanks a lot,
Svetlana
Assuming you have the error type extracted in a field called error_type
, you can do this:
your base search | stats count by error_type