<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I search for a string with a partial portion of the string? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-a-string-with-a-partial-portion-of-the/m-p/343944#M101894</link>
    <description>&lt;P&gt;Add an asterisk to the end:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"%ASA-4-71390*"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I does full &lt;EM&gt;words&lt;/EM&gt; only if you don't add the asterisk. &lt;/P&gt;</description>
    <pubDate>Wed, 20 Sep 2017 19:47:03 GMT</pubDate>
    <dc:creator>cpetterborg</dc:creator>
    <dc:date>2017-09-20T19:47:03Z</dc:date>
    <item>
      <title>How do I search for a string with a partial portion of the string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-a-string-with-a-partial-portion-of-the/m-p/343943#M101893</link>
      <description>&lt;P&gt;Can someone help explain why "partial" search doesn't work for me?&lt;/P&gt;

&lt;P&gt;It's an ASA syslog... when I search for a full syslog event "%ASA-4-713903" it finds it, when i search "%ASA-4-" the "%ASA-4-713903" is among the results, but when I search ""%ASA-4-71390" it finds nothing.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 19:33:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-a-string-with-a-partial-portion-of-the/m-p/343943#M101893</guid>
      <dc:creator>ptur</dc:creator>
      <dc:date>2017-09-20T19:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: How do I search for a string with a partial portion of the string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-a-string-with-a-partial-portion-of-the/m-p/343944#M101894</link>
      <description>&lt;P&gt;Add an asterisk to the end:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;"%ASA-4-71390*"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I does full &lt;EM&gt;words&lt;/EM&gt; only if you don't add the asterisk. &lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 19:47:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-a-string-with-a-partial-portion-of-the/m-p/343944#M101894</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2017-09-20T19:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do I search for a string with a partial portion of the string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-a-string-with-a-partial-portion-of-the/m-p/343945#M101895</link>
      <description>&lt;P&gt;For understand that behavior, you need to understand how Splunk stores the data in Splunk for text based searching. The phenomenon I'm referring to is 'Event Segmentation' and you can find all you need here:&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.2/Data/Abouteventsegmentation"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.2/Data/Abouteventsegmentation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 19:48:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-a-string-with-a-partial-portion-of-the/m-p/343945#M101895</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-09-20T19:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: How do I search for a string with a partial portion of the string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-a-string-with-a-partial-portion-of-the/m-p/343946#M101896</link>
      <description>&lt;P&gt;Hey @ptur, if @somesoni2 or @cpetterborg solved your problem, please don't forget to accept an answer! You can upvote posts as well. (Karma points will be awarded for either action.) Happy Splunking!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 23:10:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-a-string-with-a-partial-portion-of-the/m-p/343946#M101896</guid>
      <dc:creator>lfedak_splunk</dc:creator>
      <dc:date>2017-09-21T23:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: How do I search for a string with a partial portion of the string?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-a-string-with-a-partial-portion-of-the/m-p/343947#M101897</link>
      <description>&lt;P&gt;Thanks for both answers!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 23:29:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-I-search-for-a-string-with-a-partial-portion-of-the/m-p/343947#M101897</guid>
      <dc:creator>ptur</dc:creator>
      <dc:date>2017-09-21T23:29:19Z</dc:date>
    </item>
  </channel>
</rss>

