Hi
I'm trying to search for multiple strings within all fields of my index using fieldsummary, e.g.
index=centre_data
| fieldsummary
| search values="*DAN012A Dance*" OR values="*2148 FNT004F Nutrition Technology*"
| table fields
Is there another/better way to perform this search or modify this query so that I can add the field where the "string" appears in the event, as well as include other output fields of my choosing? e.g. User, Date, FieldWhereStringAppears, Object
I have tried a number of things and can't work it out.
Many thanks
If you put the sought strings in the base search then Splunk will search all fields for them. Then you can use the fields command to select the fields you want in the output.
index=centre_data ("DAN012A Dance" OR "2148 FNT004F Nutrition Technology")
| fields ...
Exactly what I needed, thank you!
If you put the sought strings in the base search then Splunk will search all fields for them. Then you can use the fields command to select the fields you want in the output.
index=centre_data ("DAN012A Dance" OR "2148 FNT004F Nutrition Technology")
| fields ...