Splunk Dev

How to search for "Roberto Carlos" in text-only files ?

wajihullahbaig
Explorer

I have just indexed a few plain text files using Splunk Web gui. Now I am trying to retrieve some results using the Java SDK. I am not sure of the search queries. What would be my search query if I want to search all the files for "Roberto Carlos" and if I need to get the top 10 results?

Guidance much appreciated as I am new to splunk.

Tags (3)
0 Karma
1 Solution

cvajs
Contributor

not knowing what your indexes or terms are called,
index=text_files " Roberto Carlos " | top filename limit=10

View solution in original post

cvajs
Contributor

not knowing what your indexes or terms are called,
index=text_files " Roberto Carlos " | top filename limit=10

wajihullahbaig
Explorer

Yes...I was just looking at the XML the search returned. Therefore it is now much easier to understand. Thanks.

cvajs
Contributor

you can see extracted fields from a general search on the left side, it will show you the fields which you can then use to act on in a search, eg "filename", etc.

wajihullahbaig
Explorer

Much appreciated. Thanks

0 Karma
Get Updates on the Splunk Community!

Splunk is Nurturing Tomorrow’s Cybersecurity Leaders Today

Meet Carol Wright. She leads the Splunk Academic Alliance program at Splunk. The Splunk Academic Alliance ...

Part 2: A Guide to Maximizing Splunk IT Service Intelligence

Welcome to the second segment of our guide. In Part 1, we covered the essentials of getting started with ITSI ...

Part 1: A Guide to Maximizing Splunk IT Service Intelligence

As modern IT environments continue to grow in complexity and speed, the ability to efficiently manage and ...