Splunk Search

how to search multiple strings

arunkumardhiman
New Member

Hi Team,

I have a list of 200 filenames (string) that need to be searched in Splunk. Each filename is unique.

example - if I have filenames like 1.txt, 2.txt, 3.txt ........ 200.txt

I am trying it like below -

(1548225008333.4546.-1092053882.Oxalis_jhsediapp02.netsentral.no.doc.xml OR 1126864-1548236892-8712_ehfd.jcloud.no.doc.xml)  |
Tags (1)
0 Karma

vnravikumar
Champion

Hi @arunkumardhiman

Try like

| makeresults 
| eval filename="1.txt" 
| where in(filename,"1.txt","2,txt","3.txt")
0 Karma

arunkumardhiman
New Member

I think I did confuse you.
I have a raw data in Splunk into which I have to first find all the events containing those filenames and then to extract the values from those events only.

0 Karma

vnravikumar
Champion

Here file name is the field in the event

0 Karma

lakshman239
Influencer

You can create a lookup with all the 20 filenames and the use a sub-search - see examples in https://docs.splunk.com/Documentation/Splunk/7.2.3/Search/Aboutsubsearches

Also, within your data, if you have a field that has the filename, pls extract it, as it will come handy when you use sub-search.

0 Karma
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...