Splunk Search

Search a word not indexed

simisreedharan
Engager

Suppose i search for a word that is not indexed by splunk, whether those logs which contain that word will be returned during search?

Tags (1)
0 Karma

MousumiChowdhur
Contributor

Hi @simisreedharan,

Yes, if your log contains that keyword it will be returned during the search. Can you elaborate more on your requirement or use case?

Thank You!

0 Karma

simisreedharan
Engager

Thanks for the reply. I just started learning splunk. So this question arose in my mind. So thought of asking.

0 Karma

DavidHourani
Super Champion

Hi @simisreedharan,

Could you please clarify your question ?

If data is not indexed by Splunk you cannot search it. If you mean to ask about searching for a word that is not extracted as a field then the answer is yes it is possible. You simply run your search as follows :

index=yourIndex "yourWordHere"

That will return any events that contain the word you are searching for.

Cheers,
David

0 Karma

simisreedharan
Engager

Thanks for the answer.

0 Karma

DavidHourani
Super Champion

you're most welcome ! please accept if it helped 😉

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...