<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search Keywords with search button in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-Keywords-with-search-button/m-p/640622#M221958</link>
    <description>&lt;P&gt;This is the search syntax:&lt;/P&gt;&lt;P&gt;&amp;lt;label&amp;gt;Message/Note Search&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;fieldset autoRun="false" submitButton="true"&amp;gt;&lt;BR /&gt;&amp;lt;input type="time" token="field1"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Time&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;-4h@m&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;input type="dropdown" token="sourcetype" searchWhenChanged="false"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Sourcetype&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;populatingSearch fieldForValue="sourcetype" fieldForLabel="sourcetype"&amp;gt;&lt;BR /&gt;&amp;lt;![CDATA[|metadata type=sourcetypes index=netfw | stats count by sourcetype]]&amp;gt;&lt;BR /&gt;&amp;lt;/populatingSearch&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;input type="text" token="*"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Message/Note&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;/fieldset&amp;gt;&lt;BR /&gt;&amp;lt;row&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;table&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;Source IP Search Results&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;search&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;index=scfw sourcetype="$sourcetype$" (msg="$*$" OR note="$*$")&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Apr 2023 15:02:17 GMT</pubDate>
    <dc:creator>ASR1022</dc:creator>
    <dc:date>2023-04-19T15:02:17Z</dc:date>
    <item>
      <title>Search Keywords with search button</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Keywords-with-search-button/m-p/640608#M221954</link>
      <description>&lt;P&gt;I am currently working on a search dashboard.&amp;nbsp; I have the dashboard created and the search (Submit Button).&amp;nbsp; In this search I am looking at the messaging portion of our firewall logs.&amp;nbsp; When I submit a search I have to put in the whole message example "Interface G1 Link is up".&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am trying to do is search for keywords like Interface, G1, link is up, link is down.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any info would be great.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 14:01:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Keywords-with-search-button/m-p/640608#M221954</guid>
      <dc:creator>ASR1022</dc:creator>
      <dc:date>2023-04-19T14:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: Search Keywords with search button</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Keywords-with-search-button/m-p/640612#M221955</link>
      <description>&lt;P&gt;When you open the search from your dashboard (after clicking on the little magnifying glass icon when you mouse hover the table/visualization), when search you get and what it should be? Are you using a text box to search for keywords? Should those keywords be used with 'OR' conjunction or 'AND'?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 14:16:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Keywords-with-search-button/m-p/640612#M221955</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2023-04-19T14:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: Search Keywords with search button</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Keywords-with-search-button/m-p/640622#M221958</link>
      <description>&lt;P&gt;This is the search syntax:&lt;/P&gt;&lt;P&gt;&amp;lt;label&amp;gt;Message/Note Search&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;fieldset autoRun="false" submitButton="true"&amp;gt;&lt;BR /&gt;&amp;lt;input type="time" token="field1"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Time&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;-4h@m&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;input type="dropdown" token="sourcetype" searchWhenChanged="false"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Sourcetype&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;&lt;BR /&gt;&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;&lt;BR /&gt;&amp;lt;populatingSearch fieldForValue="sourcetype" fieldForLabel="sourcetype"&amp;gt;&lt;BR /&gt;&amp;lt;![CDATA[|metadata type=sourcetypes index=netfw | stats count by sourcetype]]&amp;gt;&lt;BR /&gt;&amp;lt;/populatingSearch&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;input type="text" token="*"&amp;gt;&lt;BR /&gt;&amp;lt;label&amp;gt;Message/Note&amp;lt;/label&amp;gt;&lt;BR /&gt;&amp;lt;/input&amp;gt;&lt;BR /&gt;&amp;lt;/fieldset&amp;gt;&lt;BR /&gt;&amp;lt;row&amp;gt;&lt;BR /&gt;&amp;lt;panel&amp;gt;&lt;BR /&gt;&amp;lt;table&amp;gt;&lt;BR /&gt;&amp;lt;title&amp;gt;Source IP Search Results&amp;lt;/title&amp;gt;&lt;BR /&gt;&amp;lt;search&amp;gt;&lt;BR /&gt;&amp;lt;query&amp;gt;index=scfw sourcetype="$sourcetype$" (msg="$*$" OR note="$*$")&amp;lt;/query&amp;gt;&lt;BR /&gt;&amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;&lt;BR /&gt;&amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;&lt;BR /&gt;&amp;lt;/search&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 15:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Keywords-with-search-button/m-p/640622#M221958</guid>
      <dc:creator>ASR1022</dc:creator>
      <dc:date>2023-04-19T15:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Search Keywords with search button</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Keywords-with-search-button/m-p/640671#M221971</link>
      <description>&lt;P&gt;Give this a try&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;lt;label&amp;gt;Message/Note Search&amp;lt;/label&amp;gt;
&amp;lt;fieldset autoRun="false" submitButton="true"&amp;gt;
&amp;lt;input type="time" token="field1"&amp;gt;
&amp;lt;label&amp;gt;Time&amp;lt;/label&amp;gt;
&amp;lt;default&amp;gt;
&amp;lt;earliest&amp;gt;-4h@m&amp;lt;/earliest&amp;gt;
&amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
&amp;lt;/default&amp;gt;
&amp;lt;/input&amp;gt;
&amp;lt;input type="dropdown" token="sourcetype" searchWhenChanged="false"&amp;gt;
&amp;lt;label&amp;gt;Sourcetype&amp;lt;/label&amp;gt;
&amp;lt;choice value="*"&amp;gt;All&amp;lt;/choice&amp;gt;
&amp;lt;default&amp;gt;*&amp;lt;/default&amp;gt;
&amp;lt;populatingSearch fieldForValue="sourcetype" fieldForLabel="sourcetype"&amp;gt;
&amp;lt;![CDATA[|metadata type=sourcetypes index=netfw | stats count by sourcetype]]&amp;gt;
&amp;lt;/populatingSearch&amp;gt;
&amp;lt;/input&amp;gt;
&amp;lt;input type="text" token="keywords"&amp;gt;
&amp;lt;label&amp;gt;Message/Note&amp;lt;/label&amp;gt;
&amp;lt;/input&amp;gt;
&amp;lt;/fieldset&amp;gt;
&amp;lt;row&amp;gt;
&amp;lt;panel&amp;gt;
&amp;lt;table&amp;gt;
&amp;lt;title&amp;gt;Source IP Search Results&amp;lt;/title&amp;gt;
&amp;lt;search&amp;gt;
&amp;lt;query&amp;gt;index=scfw sourcetype="$sourcetype$" (msg="*$keywords$*" OR note="*$keywords$*")&amp;lt;/query&amp;gt;
&amp;lt;earliest&amp;gt;$field1.earliest$&amp;lt;/earliest&amp;gt;
&amp;lt;latest&amp;gt;$field1.latest$&amp;lt;/latest&amp;gt;
&amp;lt;/search&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;With this, you would be able to specify a single keyword OR portion of the string you're searching. (e.g. set the 'Message/Notes' textbox value to just 'G1' OR just 'Interface'.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 17:59:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Keywords-with-search-button/m-p/640671#M221971</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2023-04-19T17:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: Search Keywords with search button</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-Keywords-with-search-button/m-p/640678#M221974</link>
      <description>&lt;P&gt;That worked for me somesoni2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 18:27:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-Keywords-with-search-button/m-p/640678#M221974</guid>
      <dc:creator>ASR1022</dc:creator>
      <dc:date>2023-04-19T18:27:52Z</dc:date>
    </item>
  </channel>
</rss>

