Splunk Search

Is there a way to only search * (asterisk)?

New Member

Dear Experts ,

Please suggest an answer on a silly question

If my log contains *(star) as a word/character .

How we will be able to do it in Splunk .
As in Splunk * is considered as regex .

Is it possible.


0 Karma

Revered Legend

You can do like this

your base search | regex _raw=".*\*.*"
0 Karma


or | search match(_raw,"[*]")

0 Karma

Revered Legend

The match function is not available with | search command. Do you mean | where match(_raw,"[*]") (which works)?

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!