Splunk Search

Using wildcards in a search string

New Member

Hi All,

Can someone please explain how I use a wildcard character in the middle of a search string? For example, if I want find all gmail addresses that start with the letter 'a', I thought I could search for emailaddress="a*@gmail.com, however this returns all records. I guess I have to use a regex but my knowledge hasn't reached that level yet so I am struggling with this one.



Tags (1)
0 Karma

New Member

Is not working for me either.

I tried
index=my_index | regex my_field="^my*.value.com"

and it is not finding anything even I

Where it should match

0 Karma

Splunk Employee
Splunk Employee

other than the fact that you are missing a closing double quote in your example. That will work fine.
Is that a typo?

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!

Path Finder

Hi AB,

Strange, I just tried you're search query emailaddress="a*@gmail.com" and it worked to filter emails that starts with an a, wildcards should work like you expected.

Alternatively use the regex command to filter you're results, for you're case just append this command to you're search.

| regex emailaddress="^a.*@gmail.com"

This will find all emails that starts with an "a" and ends with "@gmail.com"

Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...