Hi Team,
I have a list of 200 filenames (string) that need to be searched in Splunk. Each filename is unique.
example - if I have filenames like 1.txt, 2.txt, 3.txt ........ 200.txt
I am trying it like below -
(1548225008333.4546.-1092053882.Oxalis_jhsediapp02.netsentral.no.doc.xml OR 1126864-1548236892-8712_ehfd.jcloud.no.doc.xml) |
Hi @arunkumardhiman
Try like
| makeresults
| eval filename="1.txt"
| where in(filename,"1.txt","2,txt","3.txt")
I think I did confuse you.
I have a raw data in Splunk into which I have to first find all the events containing those filenames and then to extract the values from those events only.
Here file name is the field in the event
You can create a lookup with all the 20 filenames and the use a sub-search - see examples in https://docs.splunk.com/Documentation/Splunk/7.2.3/Search/Aboutsubsearches
Also, within your data, if you have a field that has the filename, pls extract it, as it will come handy when you use sub-search.