Splunk Search

Search for a string containing X

mmiller77
Explorer

Hi there -

I know how to search for parameters/variables that equal X value...but how to I construct a query to look for a parameter/variable containing ______?

For instance - instead of "itemId=1234", I want to search for "itemId CONTAINS 23".

Hopefully this makes sense! 🙂

Thanks in advance for your help!

Tags (2)
1 Solution

dflodstrom
Builder

What about
itemId=$23$

Except replace $ with * .... it won't let me put wildcards around 23 because of comment formatting

View solution in original post

dflodstrom
Builder

What about
itemId=$23$

Except replace $ with * .... it won't let me put wildcards around 23 because of comment formatting

mmiller77
Explorer

Thank you @dflodstrom ! it looks like that does the trick 😄

mmiller77
Explorer

Hi @dflodstrom - thanks for your feedback!

Using:

itemId=23

...will search for the parameter/variable of "itemId" only containing the value of "23". That's not what I'm trying to do here.

I'm trying to search for a parameter that contains a value...but is not limited to ONLY that value (i.e. - does not have to EQUAL that value).

Hopefully that's a bit more clear 🙂

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...