How to do it...

Follow these steps to pivot chart the top error codes:

  1. Log in to your Splunk server.
  2. Select the Operational Intelligence application.
  3. Select the Datasets menu item from the application menu.
  4. On Web Access > All Web Access > Error dataset row, select the Explore dropdown in the Actions column and Visualize with Pivot.
  5. Configure the Pivot interface such that Filters is set to Last 24 hours, Split Rows is set to _time, _time Periods is set to Hours, Split Columns is set to status, and Column Values is set to Count of Error, as shown in the following screenshot:
  6. You should see a count by status codes over 1-hour time periods. ...

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.