You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Splunk Rex命令实现异常过滤、错误码统计及后续信息提取的技术需求

Splunk Query to Analyze Limoc Input Exceptions

Here's a complete Splunk query that addresses all your requirements:

<your_base_search>
| search "Limoc Input : Exception occurred: " \d+
| rex "Limoc Input : Exception occurred: (?<error_code>\d+) (?<error_details>.+)"
| stats count as occurrence_count by error_code, error_details
| table error_code error_details occurrence_count

Breakdown of each component:

  • Base Search: Replace <your_base_search> with your actual index, sourcetype, or time range filters (e.g., index=your_index sourcetype=your_sourcetype earliest=-24h).
  • Filter Step: The search command uses a regex to target logs matching the pattern "Limoc Input : Exception occurred: " followed by any numeric error code (covers 100, 101, and all similar numeric error formats).
  • Field Extraction: The rex command captures two key fields:
    • error_code: The numeric code immediately after the exception message.
    • error_details: All text following the error code (e.g., "COMPRESS 'success' EEEE08EE.ERROR-TEXT(1) null").
  • Count Aggregation: stats count as occurrence_count groups results by both error_code and error_details to count how many times each unique error scenario occurs.
  • Output Formatting: table arranges the results in your desired order: error code, associated details, and occurrence count.

Example Output:

Running this against your sample logs will produce a table like:

error_codeerror_detailsoccurrence_count
100COMPRESS 'success' EEEE08EE.ERROR-TEXT(1) null1
101COMPRESS 'success' EEEE08EE.ERROR-TEXT(2) null1

(Counts will update automatically based on how many times each error appears in your dataset.)

内容的提问来源于stack exchange,提问作者Diksha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.27 21:37:38