Splunk Dev

Keywords and Field name restrictions.

rahulrwt23
New Member

Can we search keywords in Splunk?
Is field name restricted to 15 characters only?
How can I name fields with more than 15 characters?

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi rahulrwt23,
to search keywords use brackets (").
you can use more than 15 chars.
You can use the name you like, remember that to use spaces in field names isn't a good idea, anyway you can do it using brackets (").
Bye.
Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi rahulrwt23,
to search keywords use brackets (").
you can use more than 15 chars.
You can use the name you like, remember that to use spaces in field names isn't a good idea, anyway you can do it using brackets (").
Bye.
Giuseppe

rahulrwt23
New Member

Thanks
It was helpful.

0 Karma

Javip
Path Finder

Splunk name field isn't restricted to 15 characters... what query are you trying to test?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...