Splunk Search

Searching for multiple strings within all fields of index

deton0
Explorer

Hi

I'm trying to search for multiple strings within all fields of my index using fieldsummary, e.g.

index=centre_data
| fieldsummary
| search values="*DAN012A Dance*" OR values="*2148 FNT004F Nutrition Technology*"
| table fields

Is there another/better way to perform this search or modify this query so that I can add the field where the "string" appears in the event, as well as include other output fields of my choosing? e.g. User, Date, FieldWhereStringAppears, Object

I have tried a number of things and can't work it out.

Many thanks

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If you put the sought strings in the base search then Splunk will search all fields for them.  Then you can use the fields command to select the fields you want in the output.

index=centre_data ("DAN012A Dance" OR "2148 FNT004F Nutrition Technology")
| fields ...

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

deton0
Explorer

Exactly what I needed, thank you!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you put the sought strings in the base search then Splunk will search all fields for them.  Then you can use the fields command to select the fields you want in the output.

index=centre_data ("DAN012A Dance" OR "2148 FNT004F Nutrition Technology")
| fields ...

 

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...