Splunk Search

Search fieldsummary values for search keyword

msrama5
Explorer

Hello, I have query below and want to search by filterstring from fieldsummary values and return all values which matches filterstring from the results of query below -
index =test environment=ps sourcetype=asp_test requestbody=* requestbody="request-body" | fields requestbody | xmlkv | fieldsummary maxvals=10

0 Karma

to4kawa
Ultra Champion
| search your_search_field="*searchvalue*"

Please remove the asterisk appropriately.

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...