Getting Data In

How to write simple search of key words or numbers?

kruane
Explorer

Say I'm just trying to find if anything in Splunk is showing number "12345678". Isn't there a way to query a simple search trying to find that? 

Or if I'm looking for a specific user; is there a way to write a query like "jsmith@gmail.com". Essentially looking for anything associated with this username or anything associated with that number above. 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @kruane,

yes all the things you said are possible.

To understand how to do it I hint to follow the Splunk Search Tutorial (https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial), to understand how to use SPL, otherwise, you can search on the Splunk Channel on YouTube some interesting video (e.g.: https://www.youtube.com/watch?v=xtyH_6iMxwA). 

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...