Splunk Search

Search for a string containing X

mmiller77
Explorer

Hi there -

I know how to search for parameters/variables that equal X value...but how to I construct a query to look for a parameter/variable containing ______?

For instance - instead of "itemId=1234", I want to search for "itemId CONTAINS 23".

Hopefully this makes sense! 🙂

Thanks in advance for your help!

Tags (2)
1 Solution

dflodstrom
Builder

What about
itemId=$23$

Except replace $ with * .... it won't let me put wildcards around 23 because of comment formatting

View solution in original post

dflodstrom
Builder

What about
itemId=$23$

Except replace $ with * .... it won't let me put wildcards around 23 because of comment formatting

mmiller77
Explorer

Thank you @dflodstrom ! it looks like that does the trick 😄

mmiller77
Explorer

Hi @dflodstrom - thanks for your feedback!

Using:

itemId=23

...will search for the parameter/variable of "itemId" only containing the value of "23". That's not what I'm trying to do here.

I'm trying to search for a parameter that contains a value...but is not limited to ONLY that value (i.e. - does not have to EQUAL that value).

Hopefully that's a bit more clear 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...