Splunk Search

Searching for multiple strings within all fields of index

deton0
Explorer

Hi

I'm trying to search for multiple strings within all fields of my index using fieldsummary, e.g.

index=centre_data
| fieldsummary
| search values="*DAN012A Dance*" OR values="*2148 FNT004F Nutrition Technology*"
| table fields

Is there another/better way to perform this search or modify this query so that I can add the field where the "string" appears in the event, as well as include other output fields of my choosing? e.g. User, Date, FieldWhereStringAppears, Object

I have tried a number of things and can't work it out.

Many thanks

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

If you put the sought strings in the base search then Splunk will search all fields for them.  Then you can use the fields command to select the fields you want in the output.

index=centre_data ("DAN012A Dance" OR "2148 FNT004F Nutrition Technology")
| fields ...

 

---
If this reply helps you, Karma would be appreciated.

View solution in original post

deton0
Explorer

Exactly what I needed, thank you!

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you put the sought strings in the base search then Splunk will search all fields for them.  Then you can use the fields command to select the fields you want in the output.

index=centre_data ("DAN012A Dance" OR "2148 FNT004F Nutrition Technology")
| fields ...

 

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...

4 Ways the Splunk Community Helps You Prepare for .conf25

.conf25 is right around the corner, and whether you’re a first-time attendee or a seasoned Splunker, the ...

Enhance Your Splunk App Development: New Tools & Support

UCC FrameworkAdd-on Builder has been around for quite some time. It helps build Splunk apps faster, but it ...