Splunk Search

Search character *

gerbert
Path Finder

Hello,

I want to make the following search:

index = "myIndex" myfield != "35*"

Is there a way to excluse all values of myfield that start with "35" except "35" itself. so for example i want to exclude:

myfield values:

35457, 35568, 351 but not 35 itself.

 

I know that in regex you can use "+" to indicate the use of "one or more" matches but I don't know how to use it in a splunk search.

 

Cheers

Fritz

Labels (1)
Tags (3)
0 Karma
1 Solution

gerbert
Path Finder

Thanks for your help but I figured it out. The search:

index = "myIndex" | regex myfield != "^(35).+"

 

gives me what i want

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gerbert,

di you tried:

index = "myIndex" myfield="35"

?

Ciao.

Giuseppe

0 Karma

gerbert
Path Finder

I need the "!=" in my search because I want to explicitly exclude some values from my search. So replacing "!=" with "=" doesn't help me.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gerbert,

let me understand your search need:

  • you want to exclude all the values where there 35 but also other,
  • you want to take only the exact value "35"

if you want to take only the exact value "35", = is the solution, what are the other need of your search so the = isn't the solution?

Ciao.

Giuseppe

0 Karma

gerbert
Path Finder

I do not want the value "35" to be excluded, which would be the case with the search myfield!="35*".

Saying i don't want the "35" excluded is different from saying I want the "35" value.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @gerbert,

Ok understood!

please try this:

index = "myIndex" (myfield!="35" OR myfield="35")

Ciao.

Giuseppe

0 Karma

gerbert
Path Finder

Thanks for your help but I figured it out. The search:

index = "myIndex" | regex myfield != "^(35).+"

 

gives me what i want

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...