Splunk Search

How do you search logs for a letter at a specific position?

arthurva
Observer

I'm very new to Splunk and need help with a search.

I want to perform a search to show me the results where the 5th letter of the server name has the letter "p". Is this possible?

Thank you

0 Karma
1 Solution

Vijeta
Influencer

@arthurva Suppose your index is test and your field is server_name.

index=test| eval x = substr(server_name,5,1)| where x="p"

View solution in original post

0 Karma

vnravikumar
Champion

Hi @arthurva

Give a try

| makeresults 
| eval test="ABCDPTD" 
| regex test="^.{4,4}[p|P]"
0 Karma

Vijeta
Influencer

@arthurva Suppose your index is test and your field is server_name.

index=test| eval x = substr(server_name,5,1)| where x="p"
0 Karma

arthurva
Observer

That worked. Thank you!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...