如何将Splunk多个独立查询的统计结果合并生成饼图?
解决方法
方法1:用append拼接子查询并指定异常类型
每个子查询手动标记对应的异常类型,合并后按类型统计,直接生成可视化图表:
index=index source="source" "Exception 1" | eval ExceptionType="Exception 1" | append [ search index=index source="source" "Exception 2" | eval ExceptionType="Exception 2" ] | append [ search index=index source="source" "Exception 3" | eval ExceptionType="Exception 3" ] | append [ search index=index source="source" "Exception 4" | eval ExceptionType="Exception 4" ] | stats count as Total by ExceptionType
方法2:用OR组合搜索+case判断类型
一次搜索所有目标异常,通过case匹配日志内容标记类型,写法更简洁:
index=index source="source" ("Exception 1" OR "Exception 2" OR "Exception 3" OR "Exception 4") | eval ExceptionType=case( match(_raw, "Exception 1"), "Exception 1", match(_raw, "Exception 2"), "Exception 2", match(_raw, "Exception 3"), "Exception 3", match(_raw, "Exception 4"), "Exception 4" ) | stats count as Total by ExceptionType
关于multisearch的正确用法
之前尝试失败大概率是子查询未统一返回字段,给每个子查询添加eval标记类型即可正常使用:
| multisearch [search index=index source="source" "Exception 1" | eval ExceptionType="Exception 1"] [search index=index source="source" "Exception 2" | eval ExceptionType="Exception 2"] [search index=index source="source" "Exception 3" | eval ExceptionType="Exception 3"] [search index=index source="source" "Exception 4" | eval ExceptionType="Exception 4"] | stats count as Total by ExceptionType
是否需要优化日志
临时需求用上述方法足够,但如果后续需频繁新增异常类型,手动维护查询会很繁琐。长期来看建议优化日志格式,将异常类型作为单独的结构化字段(比如JSON、键值对形式),这样无需修改查询,直接按字段统计即可。
内容的提问来源于stack exchange,提问作者Jatin Shekara
相关产品推荐
相关产品推荐

