I have TYPE field, that have a value of *, **, ***.
When I'm trying to |search TYPE="*" (all of the events will be shown, all of the values)
and when I use |regex TYPE="\*" (all of the *,**,** will be shown.)
I need help for searching * ,**, *** in a specific field..
Welp, just came across your question and was wondering the same thing, not great news:
Splunk SPL uses the asterisk ( * ) as a wildcard character. The backslash cannot be used to escape the asterisk in search strings.