Splunk Search

What is the best way to search email subjects by "is" or "contains"?

packet_hunter
Contributor

Scenarios:

1) searching email logs for an exact subject so I use quotes

index=mail sourcetype=xemail subject = "exact subject"

2) searching email logs for subjects that contains [blah blah] so I use *

index=mail sourcetype=xemail subject = *blah blah*

But what about * "blah blah" or * "blah blah" * or "blah blah" * ?

Can anyone explain the best way to search by "is" or "contains" ?

Thank you

0 Karma
1 Solution

somesoni2
Revered Legend

It should be "blah blah" , preferably inside double quotes, for 'contains'. For 'is', subject="Full exact string" shoud work fine.

View solution in original post

0 Karma

somesoni2
Revered Legend

It should be "blah blah" , preferably inside double quotes, for 'contains'. For 'is', subject="Full exact string" shoud work fine.

0 Karma

packet_hunter
Contributor

Thank you, you are correct, I was just wondering about the * because that works too but I will use your method 🙂

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...