Splunk Search

Search for a string containing X

mmiller77
Explorer

Hi there -

I know how to search for parameters/variables that equal X value...but how to I construct a query to look for a parameter/variable containing ______?

For instance - instead of "itemId=1234", I want to search for "itemId CONTAINS 23".

Hopefully this makes sense! 🙂

Thanks in advance for your help!

Tags (2)
1 Solution

dflodstrom
Builder

What about
itemId=$23$

Except replace $ with * .... it won't let me put wildcards around 23 because of comment formatting

View solution in original post

dflodstrom
Builder

What about
itemId=$23$

Except replace $ with * .... it won't let me put wildcards around 23 because of comment formatting

mmiller77
Explorer

Thank you @dflodstrom ! it looks like that does the trick 😄

mmiller77
Explorer

Hi @dflodstrom - thanks for your feedback!

Using:

itemId=23

...will search for the parameter/variable of "itemId" only containing the value of "23". That's not what I'm trying to do here.

I'm trying to search for a parameter that contains a value...but is not limited to ONLY that value (i.e. - does not have to EQUAL that value).

Hopefully that's a bit more clear 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...