Splunk Search

exclude asterisk character from a search

gcusello
SplunkTrust
SplunkTrust

Hi at all,
I have a field (called uid) with some values = "*" and I'd like to exclude them from the results of my search.
I tried with uid="*" but Splunk read asterisk as a wildcard.
How can I do this?
Thanks in advance.
Giuseppe

0 Karma
1 Solution

woodcock
Esteemed Legend

The base SPL always treats asterisk as wildcard and it cannot be escaped. However, there are several ways to do this by piping to where, such as like or match (you could also pipe to regex😞

... | where NOT match(uid, "\*")

View solution in original post

chimell
Motivator

Hi cusello
Try this search code

......|table uid |where isnotnull(uid)

Look at an example

sourcetype=access_* |table  categoryId |where isnotnull(categoryId) 

It works well

0 Karma

woodcock
Esteemed Legend

The base SPL always treats asterisk as wildcard and it cannot be escaped. However, there are several ways to do this by piping to where, such as like or match (you could also pipe to regex😞

... | where NOT match(uid, "\*")

Arun_N_007
Communicator

Why dont you Try with where command it will work

..|where uid=="*"

Arun_N_007
Communicator

Here you can use NOT operator along with where to exclude.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...