<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: newbie question in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/newbie-question/m-p/153114#M42950</link>
    <description>&lt;P&gt;The data is in JSOn format, would that make a difference?&lt;/P&gt;</description>
    <pubDate>Fri, 22 Nov 2013 21:59:41 GMT</pubDate>
    <dc:creator>simplywibble</dc:creator>
    <dc:date>2013-11-22T21:59:41Z</dc:date>
    <item>
      <title>newbie question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/newbie-question/m-p/153111#M42947</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;basic question.&lt;/P&gt;

&lt;P&gt;How do i search data and return results on content that has a colon in it?&lt;/P&gt;

&lt;P&gt;Such as&lt;/P&gt;

&lt;P&gt;Server: Apache&lt;BR /&gt;
Server: Apache/2.2.3&lt;/P&gt;

&lt;P&gt;or&lt;/P&gt;

&lt;P&gt;Content-Length: 200&lt;/P&gt;

&lt;P&gt;Do i need to use regex to break it out?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;

&lt;P&gt;Dan&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2013 19:22:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/newbie-question/m-p/153111#M42947</guid>
      <dc:creator>simplywibble</dc:creator>
      <dc:date>2013-11-22T19:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/newbie-question/m-p/153112#M42948</link>
      <description>&lt;P&gt;surrounding the search string in double quotes should be sufficient (ie.  "Server: Apache").  Is that not working?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2013 19:25:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/newbie-question/m-p/153112#M42948</guid>
      <dc:creator>anssntaco</dc:creator>
      <dc:date>2013-11-22T19:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/newbie-question/m-p/153113#M42949</link>
      <description>&lt;P&gt;As far as I have seen, you can directly provide the content in the search and it works with (best practice) or without quotes.&lt;BR /&gt;
e.g.  index=abc http://&lt;BR /&gt;&lt;BR /&gt;
index=abc "http://"&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2013 19:48:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/newbie-question/m-p/153113#M42949</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2013-11-22T19:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question</title>
      <link>https://community.splunk.com/t5/Splunk-Search/newbie-question/m-p/153114#M42950</link>
      <description>&lt;P&gt;The data is in JSOn format, would that make a difference?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2013 21:59:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/newbie-question/m-p/153114#M42950</guid>
      <dc:creator>simplywibble</dc:creator>
      <dc:date>2013-11-22T21:59:41Z</dc:date>
    </item>
  </channel>
</rss>

