Splunk Search

Finding substrings

sloshburch
Ultra Champion

When searching for

index=myindex exception

I only get events with the text "exception" surrounded by term separators. Does anyone have any tips for how to also end up getting events with text like "this.is.AnExceptionEvent".

The only way I can think of is to search for "*exception*" but that ends up taking forever because of the massive amount of data that must be searched.

Can anyone spot any trick I've overlooked?

Tags (1)
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Searching for *exception* is the way to go, and you're right that it'll take ages. That's because using a wildcard at the beginning of a search phrase kills any chance of looking that up in the index structures. Instead, Splunk has to churn through all the raw data... that's regardless of whether you search for *exception* or field=*exception* in case of search time extraction.

I see two "tricks" you can try. See if there are other identifying keywords for your exception events. If there is, add those to your search to see it speed up massively.
If that's not the case you can consider extracting that field at index time. You'll add a bit of processing overhead to the indexer, but if you search for that field frequently you get that back many times over.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Searching for *exception* is the way to go, and you're right that it'll take ages. That's because using a wildcard at the beginning of a search phrase kills any chance of looking that up in the index structures. Instead, Splunk has to churn through all the raw data... that's regardless of whether you search for *exception* or field=*exception* in case of search time extraction.

I see two "tricks" you can try. See if there are other identifying keywords for your exception events. If there is, add those to your search to see it speed up massively.
If that's not the case you can consider extracting that field at index time. You'll add a bit of processing overhead to the indexer, but if you search for that field frequently you get that back many times over.

sloshburch
Ultra Champion

Thanks for elaborating. That's what I feared but I was optimistic that maybe I overlooked something trivial. Looks like we're all on the same page. Thanks!

0 Karma

sloshburch
Ultra Champion

I know what you mean. I have the message payload in a field but that still seems to be a slog because its a massive amount of data.

0 Karma

aweitzman
Motivator

Is the text extracted into a known field? Searching for field="*exception*" instead of just *exception* tends to be faster.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...