Splunk Search

Field extraction for space


Hi Team,

We have one field as Customer=ABC DEF where one space in between  where if i am giving any as Customer = *DEF* then its not giving any value..


Labels (1)
0 Karma


hi @Susha,

Provide string in double quotes.

| makeresults 
| eval Customer="ABC DEF" 
| search Customer="*DEF*"
0 Karma


thanks @manjunathmeti . but its not working since we have  value as 

Customer="ABC DEF" 

 where ABC keeps changing..

also i am getting below error :-

Error in 'makeresults' command: This command must be the first command of a search. 

0 Karma
Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...