Splunk Dev

How to search for "Roberto Carlos" in text-only files ?

wajihullahbaig
Explorer

I have just indexed a few plain text files using Splunk Web gui. Now I am trying to retrieve some results using the Java SDK. I am not sure of the search queries. What would be my search query if I want to search all the files for "Roberto Carlos" and if I need to get the top 10 results?

Guidance much appreciated as I am new to splunk.

Tags (3)
0 Karma
1 Solution

cvajs
Contributor

not knowing what your indexes or terms are called,
index=text_files " Roberto Carlos " | top filename limit=10

View solution in original post

cvajs
Contributor

not knowing what your indexes or terms are called,
index=text_files " Roberto Carlos " | top filename limit=10

wajihullahbaig
Explorer

Yes...I was just looking at the XML the search returned. Therefore it is now much easier to understand. Thanks.

cvajs
Contributor

you can see extracted fields from a general search on the left side, it will show you the fields which you can then use to act on in a search, eg "filename", etc.

wajihullahbaig
Explorer

Much appreciated. Thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...