how do you search for hash value in splunk? Do we need to use a specific index?
More words are needed to understand your use case. Hash value of what? What problem are you trying to solve?
We have a list of hash values for a possible ransomeware attack and need to see if those hashes were ever in our environment.
If you have the hashes in Splunk - perhaps reported by a firewall or email server - then, yes, you can search for them. They will be in the index in which they were saved.
If the hashes are not indexed in Splunk then you'll have a hard time searching for them.