Splunk Search

newbie question

New Member


basic question.

How do i search data and return results on content that has a colon in it?

Such as

Server: Apache
Server: Apache/2.2.3


Content-Length: 200

Do i need to use regex to break it out?



Tags (3)
0 Karma

Revered Legend

As far as I have seen, you can directly provide the content in the search and it works with (best practice) or without quotes.
e.g. index=abc http://

index=abc "http://"

0 Karma

Path Finder

surrounding the search string in double quotes should be sufficient (ie. "Server: Apache"). Is that not working?

0 Karma

New Member

The data is in JSOn format, would that make a difference?

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...