Getting Data In

How can I search within the source names and source type names?

mdickey
Engager

I'm using an existing Splunk instance that already has hundreds of sources and source types. How can I search among the source names and source type names to find sources of interest? For example, I would like to know the names of all sources that contain the string "prod" in the source name itself.

0 Karma
1 Solution

lguinn2
Legend

That's easy, just search

| metadata type=sources | where match(source,"prod")

or

| metadata type=sourcetypes | where match(sourcetype,"prod")

to get just a list of the sourceytpes or sources, with a little info about each. Note that the match function uses regular expressions. To actually search the data, you can use

source="*prod*"

or

sourcetype="*prod*"

HTH

View solution in original post

lguinn2
Legend

That's easy, just search

| metadata type=sources | where match(source,"prod")

or

| metadata type=sourcetypes | where match(sourcetype,"prod")

to get just a list of the sourceytpes or sources, with a little info about each. Note that the match function uses regular expressions. To actually search the data, you can use

source="*prod*"

or

sourcetype="*prod*"

HTH

lguinn2
Legend

Thanks for the catch on the typo, I fixed it!

0 Karma

mdickey
Engager

Wow, that works like magic, thanks!!

One tiny typo in the second one:
match(sourcetypes,"prod")
should be
match(sourcetype,"prod")

Thanks again!

0 Karma

lguinn2
Legend

Updated my answer per your comments!

0 Karma

mdickey
Engager

Sorry, I must not have explained myself well. Your suggestion will search the actual event data. I don't want to search the data. I only want to get a back a list of source names that match. I want to search this list of source names themselves, not the data in the sources.

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...