Splunk Search

Is there a way to search for a comma in Splunk query?

siksaw33
Path Finder

is there away we can search for a ,  to find multi locale or multi country
basically instead of the underlined


index=personmetrics logtype=personactivity wrk_grp="Ret,Ce" locale="en-US,en-GB"


1.  how do we write?

index=ccpmetrics logtype=ccpactivity (wrk_grp LIKE "," OR locale LIKE ",")
|table personname,wrk_grp,locale

2. bonus point: and then find the stats of personname and corresoponding entries.

Labels (4)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@siksaw33 - Try:

index=ccpmetrics logtype=ccpactivity (wrk_grp="*,*" OR locale="*,*")
|table personname, wrk_grp, locale

 

I hope this helps!!! Karma/upvote would be appreciated!!!

View solution in original post

VatsalJagani
SplunkTrust
SplunkTrust

@siksaw33 - Try:

index=ccpmetrics logtype=ccpactivity (wrk_grp="*,*" OR locale="*,*")
|table personname, wrk_grp, locale

 

I hope this helps!!! Karma/upvote would be appreciated!!!

gcusello
SplunkTrust
SplunkTrust

Hi @siksaw33,

you should try the IN clause:

index=personmetrics logtype=personactivity wrk_grp IN ("Ret,Ce") locale IN ("en-US,en-GB")

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...