Splunk Search

Why do wildcards in the middle of a string produce inconsistent results?

ddrillic
Ultra Champion

The studying material says that -

-- Wildcards in the middle of a string produce inconsistent results.

Why is it?

0 Karma
1 Solution

micahkemp
Champion
0 Karma

woodcock
Esteemed Legend
0 Karma

micahkemp
Champion

Check out the Splunk .conf talk by Martin Mueller:

https://conf.splunk.com/files/2017/slides/fields-indexed-tokens-and-you.pdf

Page 18 of 32.

0 Karma

nickhills
Ultra Champion

sounds like one for @martin_mueller to help with then 🙂

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

I would say thats not correct at all.

String matching is very predictable, and I frequently match all kinds of things with *'s in the middle.

host=-uk--* matches LIVE-uk-web-02 perfectly.
Never had any problem with it.

Are you sure it didn't say "inefficient" - a query filled with wildcards is not as fast as something specifically defined

If my comment helps, please give it a thumbs up!
0 Karma

somesoni2
Revered Legend

From which documentation is this?

0 Karma

ddrillic
Ultra Champion

From the *Splunk Fundamentals Part 2 (IOD) * course.

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...