<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: search for a string containing any substring that is typed in the text input in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/search-for-a-string-containing-any-substring-that-is-typed-in/m-p/576604#M200946</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/30057"&gt;@anooshac&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you share your dashboard or your search?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with this info we can help you better&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 29 Nov 2021 11:19:45 GMT</pubDate>
    <dc:creator>aasabatini</dc:creator>
    <dc:date>2021-11-29T11:19:45Z</dc:date>
    <item>
      <title>search for a string containing any substring that is typed in the text input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-for-a-string-containing-any-substring-that-is-typed-in/m-p/576590#M200942</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have a text input for a table header. My requirement is , by default the table should show all the values and if any letters typed in the text box, the same should match with the table header and the values containing that sub string should be displayed. I created the text box but haven't figured out how to match this sub string to the header. Please help me in this..&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 10:39:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-for-a-string-containing-any-substring-that-is-typed-in/m-p/576590#M200942</guid>
      <dc:creator>anooshac</dc:creator>
      <dc:date>2021-11-29T10:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: search for a string containing any substring that is typed in the text input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-for-a-string-containing-any-substring-that-is-typed-in/m-p/576604#M200946</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/30057"&gt;@anooshac&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you share your dashboard or your search?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with this info we can help you better&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 11:19:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-for-a-string-containing-any-substring-that-is-typed-in/m-p/576604#M200946</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-11-29T11:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: search for a string containing any substring that is typed in the text input</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-for-a-string-containing-any-substring-that-is-typed-in/m-p/576609#M200948</link>
      <description>&lt;P&gt;This input is to type the sub string.Default value should be all data. The search string can contain 1 or more letters, it should match the task _name in the query below and produce the table for the same.&lt;/P&gt;&lt;P&gt;&amp;lt;input type="text" token="Tok_task"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Task Name&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;/P&gt;&lt;P&gt;The query used for table is(since i cannot write the actual query here I have used examples),&lt;/P&gt;&lt;P&gt;index= "abc" sourcetype="xyz"| rex field=URL "(?&amp;amp;lt;http&amp;amp;gt;[^/]*)://(?&amp;amp;lt;group_name&amp;amp;gt;[^/]*)/(?&amp;amp;lt;project_name&amp;amp;gt;[^/]*)/(?&amp;amp;lt;task_name&amp;amp;gt;[^/]*)"| table task_name URL project_name group_name&lt;/P&gt;&lt;P&gt;I tried to add the token from input directly in the query, but it is not working. Can you please help with this one?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 12:45:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-for-a-string-containing-any-substring-that-is-typed-in/m-p/576609#M200948</guid>
      <dc:creator>anooshac</dc:creator>
      <dc:date>2021-11-29T12:45:54Z</dc:date>
    </item>
  </channel>
</rss>

