Splunk Search

Search by file name?

dgarstang
Engager

As an admin that's used to searching logs with /bin/less, ? and /, I find the Splunk web interface pretty confusing.

How can I limit searches in the web UI to specific source file names? In fact, I can't even see where Splunk even shows the name of the file that searches appeared in. This is really confusing. If I don't know what file a match was in, I really have no context of what I am seeing.

Doug.

Tags (1)
1 Solution

chris
Motivator

Hi Doug

You can search for a specific file by specifying a file name for the source in the search field. In the example "spam" and "bytes" are the searchterms and the first part (source=/directory/file.log) limits the search to a source which is a file in this case

If you select the source as a field using "Pick fields" every event ( this usually corresponds to one line in a logfile) will show it's source.

alt text

I hope this helps

Chris

View solution in original post

chris
Motivator

Hi Doug

You can search for a specific file by specifying a file name for the source in the search field. In the example "spam" and "bytes" are the searchterms and the first part (source=/directory/file.log) limits the search to a source which is a file in this case

If you select the source as a field using "Pick fields" every event ( this usually corresponds to one line in a logfile) will show it's source.

alt text

I hope this helps

Chris

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...