Splunk Search

How to display multiple search values as search coumns in the search table

kodali21055
New Member

Hi,

My application has lot of error codes(all most 35) which logs in the log file. I want to get count of each error code from the log file. For that I have written the rex as
rex "(?\d+)" | chart count by DIID, cbs2_error_code
Which is giving the out put till only 10 error codes and rest of them comes under OTHER

For eg:
20009 21002 21003 21999 25002 25017 25100 25107 25111 25113 OTHER
20 35 5 8 10 14 20 12 11 10 40

But I have lot of other error codes like 10001, 10002, 10003,.. which all are come under OTHER

Can some one help me how best I can get the report with count of each error code in the log file?

Thanks In Advance

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...