Splunk Search

Use wildcard in source?

nishantjiit
New Member

I have a directory C:\logs

in this directory I have multiple files:

1: logging-projectname-0.log (There can be multiple files like *-1.log, *-2.log etc..)
2: logging-projectname-batch-0.log (There can be multiple files like *batch-1.log, *batch-2.log etc..)

I only want to search the files like #1. So, I tried ---- source="c:\logs\logging-projectname-[0-9]{1,}.log" SEARCH_STRING

It's not working. Can anyone suggest?

Thanks in advance.

0 Karma
1 Solution

somesoni2
Revered Legend

Another option would be this

your base search | regex source="c:\\\\logs\\\\logging-projectname-\d+\.log"

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

source uses wildcards, not regular expressions. somesoni2's suggestion should work.

---
If this reply helps you, Karma would be appreciated.
0 Karma

somesoni2
Revered Legend

Another option would be this

your base search | regex source="c:\\\\logs\\\\logging-projectname-\d+\.log"

nishantjiit
New Member

Thanks it worked

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@nishantjiit, please accept an answer.

---
If this reply helps you, Karma would be appreciated.
0 Karma

skalliger
Motivator

Why don't you just use a wildcard like you mentioned it yourself?
Nevermind that.

Skalli

edit: deleted my search string.

0 Karma

xavierashe
Contributor

This should be an OR, not an AND.

0 Karma

skalliger
Motivator

Oh, you're correct. I've misread that. Thought he wants only one but not the other one.

I'll edit it.

0 Karma

horsefez
Motivator

@skalliger
stop being a noob 😛 😄

0 Karma

skalliger
Motivator

Should have deleted my comment. 😄

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...