I'm very new to Splunk and this is likely an obvious answer or I have skimmed across documentation and missed it.
So at the moment, we are ingesting logs from Google cloud, and I am interested in finding specific words such as 'error', 'fail', etc. However, I do not know the specific field name where this might appear.
Is there a search I could run as a sort of catch all that could pick up on this within our environment?
Something like the below?
index="gcp_logs" (message contains 'error' OR 'fail*')