Splunk Search

Will using a wildcard with where work?

brcox9090
New Member

I am trying to get a wildcard to work with a where clause. Not sure if I'm doing something wrong altogether or just missing some syntax but my search is as follows:

 

index=my_index | where description=" Changed * role to * Admin"

 

basically looking up whether any user had their role changed to any admin role. Thought this would be an easy one, and it is not.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The where command does not support wildcards.  As @gcusello says, use the search command or, best, put the text in the base search.

To use wildcards in where, we need to use either the match or like function.

| where match(_raw, " Changed .* role to .* Admin")

| where like(_raw, " Changed % role to % Admin")

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @brcox9090,

why do you want to use where?

is there something between the main search and the where command?

if yes, Anyway, use the search command, instead where.

otherwise, you can put all in the main search so you'll have a more performant search.

index=my_index description=" Changed * role to * Admin"

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...