Knowledge Management

Why can't you use a wildcard when searching for tags (tag=*)?

fmarquez-miles_
Splunk Employee
Splunk Employee

I've always known that you can't search tag=* but I never knew why. Maybe the old-time splunkers can elighten me?

0 Karma

renjith_nair
Legend

It's possible to search by tag=*. Are you getting any error or no results are returned.

I have created a tag for two sourcetypes and both are returned. Splunk just expands the search by substituting each value of tag with OR condition. You can have a look at the job inspector to see your final search and it might provide you the reason. For eg: you have two contradictory searches joined with OR . I

See attached screen shotalt text

It might be a permission issue also . for eg: index by default is not enabled and always have to provide index=yourindex in the search

---
What goes around comes around. If it helps, hit it with Karma 🙂
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...