Splunk Search

Why do wildcards in the middle of a string produce inconsistent results?

ddrillic
Ultra Champion

The studying material says that -

-- Wildcards in the middle of a string produce inconsistent results.

Why is it?

0 Karma
1 Solution

micahkemp
Champion
0 Karma

woodcock
Esteemed Legend
0 Karma

micahkemp
Champion

Check out the Splunk .conf talk by Martin Mueller:

https://conf.splunk.com/files/2017/slides/fields-indexed-tokens-and-you.pdf

Page 18 of 32.

0 Karma

nickhills
Ultra Champion

sounds like one for @martin_mueller to help with then 🙂

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

I would say thats not correct at all.

String matching is very predictable, and I frequently match all kinds of things with *'s in the middle.

host=-uk--* matches LIVE-uk-web-02 perfectly.
Never had any problem with it.

Are you sure it didn't say "inefficient" - a query filled with wildcards is not as fast as something specifically defined

If my comment helps, please give it a thumbs up!
0 Karma

somesoni2
SplunkTrust
SplunkTrust

From which documentation is this?

0 Karma

ddrillic
Ultra Champion

From the *Splunk Fundamentals Part 2 (IOD) * course.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...