<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to search and filter by a field that contains spaces? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-and-filter-by-a-field-that-contains-spaces/m-p/680419#M232559</link>
    <description>&lt;P&gt;You should able to do that with enclosing your field name with dollar sign ($)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;$Application Server$="running"&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;Refer to: &lt;A href="https://community.splunk.com/t5/Splunk-Search/Search-field-names-with-spaces-in-map-command-inner-search/m-p/241379#M71778" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Search/Search-field-names-with-spaces-in-map-command-inner-search/m-p/241379#M71778&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2024 16:53:24 GMT</pubDate>
    <dc:creator>JL99</dc:creator>
    <dc:date>2024-03-12T16:53:24Z</dc:date>
    <item>
      <title>How to search and filter by a field that contains spaces?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-and-filter-by-a-field-that-contains-spaces/m-p/268092#M80647</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;

&lt;P&gt;I could see a lot of discussions on this forum, but none solving my issue.&lt;/P&gt;

&lt;P&gt;I have a log with content like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;field number1: value1, Application Server=running, Database Server=running
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When I try these searches:&lt;BR /&gt;
&lt;CODE&gt;Server="running"&lt;/CODE&gt; works fine, but with &lt;CODE&gt;'Application Server'="running"&lt;/CODE&gt; or &lt;CODE&gt;"Application Server"="running"&lt;/CODE&gt; it's not. How can I filter by value of a field which has a space? I need to have logs with Application Server running (not Database Server running).&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Michal&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 13:06:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-and-filter-by-a-field-that-contains-spaces/m-p/268092#M80647</guid>
      <dc:creator>teknet7</dc:creator>
      <dc:date>2016-05-24T13:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to search and filter by a field that contains spaces?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-and-filter-by-a-field-that-contains-spaces/m-p/268093#M80648</link>
      <description>&lt;P&gt;When you view the raw events in verbose search mode you should see the field names.  What is the field name?  If it is just "server" you should consider creating either an EXTRACT or REPORT in the props.conf for that source or sourcetype.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 14:32:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-and-filter-by-a-field-that-contains-spaces/m-p/268093#M80648</guid>
      <dc:creator>sjohnson_splunk</dc:creator>
      <dc:date>2016-05-24T14:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to search and filter by a field that contains spaces?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-and-filter-by-a-field-that-contains-spaces/m-p/268094#M80649</link>
      <description>&lt;P&gt;If you're looking for events with Server fields &lt;STRONG&gt;&lt;EM&gt;containing&lt;/EM&gt;&lt;/STRONG&gt; "running bunny", this works for me:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Server=*"running bunny"*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 08 Aug 2017 13:52:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-and-filter-by-a-field-that-contains-spaces/m-p/268094#M80649</guid>
      <dc:creator>jsven7</dc:creator>
      <dc:date>2017-08-08T13:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to search and filter by a field that contains spaces?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-and-filter-by-a-field-that-contains-spaces/m-p/680419#M232559</link>
      <description>&lt;P&gt;You should able to do that with enclosing your field name with dollar sign ($)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;PRE&gt;$Application Server$="running"&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;Refer to: &lt;A href="https://community.splunk.com/t5/Splunk-Search/Search-field-names-with-spaces-in-map-command-inner-search/m-p/241379#M71778" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Splunk-Search/Search-field-names-with-spaces-in-map-command-inner-search/m-p/241379#M71778&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 16:53:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-and-filter-by-a-field-that-contains-spaces/m-p/680419#M232559</guid>
      <dc:creator>JL99</dc:creator>
      <dc:date>2024-03-12T16:53:24Z</dc:date>
    </item>
  </channel>
</rss>

