I have a list of 200 filenames (string) that need to be searched in Splunk. Each filename is unique.
example - if I have filenames like 1.txt, 2.txt, 3.txt ........ 200.txt
I am trying it like below -
(1548225008333.4546.-1092053882.Oxalis_jhsediapp02.netsentral.no.doc.xml OR 1126864-1548236892-8712_ehfd.jcloud.no.doc.xml) |
I think I did confuse you.
I have a raw data in Splunk into which I have to first find all the events containing those filenames and then to extract the values from those events only.
You can create a lookup with all the 20 filenames and the use a sub-search - see examples in https://docs.splunk.com/Documentation/Splunk/7.2.3/Search/Aboutsubsearches
Also, within your data, if you have a field that has the filename, pls extract it, as it will come handy when you use sub-search.