Splunk Search

What kind of request you need to create to select all the logs in which all fields are filled?

New Member

What kind of request you need to create to select all the logs in which all fields are filled?

Tags (2)
0 Karma

Champion

It is a search that extracts only the event that the field exists.

ex) Extract the event that fields01,fields02,fields03 exists.

index=your_index fields01=*  fields02=* fields03=*
0 Karma

New Member

Thanks, it's very useful!

0 Karma