Splunk Search

Use wildcard in source?

nishantjiit
New Member

I have a directory C:\logs

in this directory I have multiple files:

1: logging-projectname-0.log (There can be multiple files like *-1.log, *-2.log etc..)
2: logging-projectname-batch-0.log (There can be multiple files like *batch-1.log, *batch-2.log etc..)

I only want to search the files like #1. So, I tried ---- source="c:\logs\logging-projectname-[0-9]{1,}.log" SEARCH_STRING

It's not working. Can anyone suggest?

Thanks in advance.

0 Karma
1 Solution

somesoni2
Revered Legend

Another option would be this

your base search | regex source="c:\\\\logs\\\\logging-projectname-\d+\.log"

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

source uses wildcards, not regular expressions. somesoni2's suggestion should work.

---
If this reply helps you, Karma would be appreciated.
0 Karma

somesoni2
Revered Legend

Another option would be this

your base search | regex source="c:\\\\logs\\\\logging-projectname-\d+\.log"

nishantjiit
New Member

Thanks it worked

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@nishantjiit, please accept an answer.

---
If this reply helps you, Karma would be appreciated.
0 Karma

skalliger
SplunkTrust
SplunkTrust

Why don't you just use a wildcard like you mentioned it yourself?
Nevermind that.

Skalli

edit: deleted my search string.

0 Karma

xavierashe
Contributor

This should be an OR, not an AND.

0 Karma

skalliger
SplunkTrust
SplunkTrust

Oh, you're correct. I've misread that. Thought he wants only one but not the other one.

I'll edit it.

0 Karma

horsefez
Motivator

@skalliger
stop being a noob 😛 😄

0 Karma

skalliger
SplunkTrust
SplunkTrust

Should have deleted my comment. 😄

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...