Splunk Search

is * supported?


Is the wildcard search star * supported by logs in splunk? Im trying to see if splunk is seeing changes being made in log files..

Splunk Employee
Splunk Employee

Splunk supports the asterisk (*) wildcard for searching. Searching for * by itself means "match all" and returns all events. Searching for * as part of a word matches based on that word: for example fail* matches fail, failure, and failures. See also:


I am not sure which changes you try to identify, but you can use fschange to detect chages in files.

See also:


Hope that answers your question?




yeah, that helps, thanks alot

Super Champion

BTW, searching for a literal '' in your search is not currently supported (unless you disable '' as a wildcard)