Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Counting by error text

$
0
0
Hi everyone, I am trying to do the following in splunk but its not working: index=MRM eventtype=MRM_ERROR | eval Description=case( like(search, "%error1%"),"error1", like(search, "%error2%"),"error2" ) | chart count by Description Any ideas?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>