Splunk Search

How to check field values containing an underscore in splunk?

iamarkaprabha
Contributor

Hi All,

I was trying to filter out the usernames which contains underscore in splunk.
I had tried with regex Account_Name="._." and Account_Name="_"

But results are coming with all the values containing special characters in their value like arka$123 or arka&

Can you explain how to overcome this kind of situation

0 Karma

mclane1
Path Finder

Hello, any answer for this question.

In search mode, like others people say : you can search

<your_search> field=*_*

In like command, underscore (like percent) is a wildcard (percent is ".*" and underscore is "."). You have to use match with real regex. Exemple :

<your_search> | where match(field,".*_.*")

 

0 Karma

Richfez
SplunkTrust
SplunkTrust

A run-anywhere:

| makeresults | eval test="Billy_Sally" | search test="*_*"

This searches for events that have a field named test, and where that field's contents have an underscore. In this test case the event shows up (e.g. the search matches).

Compare that with

| makeresults | eval test="Billy_Sally" | search test!="*_*"

This searches for events that have a field named test, but where that fields contents do not have an underscore. If you run this search, nothing shows up.

In your case, make sure you are using != .

Happy Splunking,
Rich

harsmarvania57
Ultra Champion

Hi

Please try to run <yourBaseSearch> Account_Name=*_*

I have created run anywhere search which is only searching values with _ from field1

| makeresults | eval field1="abc_test"
| append [ makeresults | eval field1="abc123&" ]
| search field1=*_*

I hope this helps.

0 Karma
Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...