Splunk Search

Search by source name in virtual index does not show results

sdaruna
Explorer

Hi,

i need to get the raw data of file based on source file name. For that i have used below query.

source="xml_file_1.xml" | table _raw

This is giving results only for local indexes, but not the virtual indexes.
I tried below queries as well,

index ="hdfs_index" | search source="xml_file_1.xml" | table _raw
index ="hdfs_index" WHERE source="xml_file_1.xml" | table _raw

But, none has given results.
What went wrong.

Is there a way that i can match the source file name.?

Tags (1)
0 Karma

javiergn
Super Champion

What about the following using a wildcard for your source?

index ="hdfs_index" source="*xml_file_1.xml" | table _raw

Apologies if I'm missing something here.

0 Karma

sdaruna
Explorer

In fact, i missed a point here. The source will be name in virtual indexes will have full path.

I tried below one and worked.

index="hdfs_index" | eval source = replace(source, ".*/", "") | search source="xml_file_0.xml" | table _raw

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...