Splunk Search

newbie question

New Member

Hi

basic question.

How do i search data and return results on content that has a colon in it?

Such as

Server: Apache
Server: Apache/2.2.3

or

Content-Length: 200

Do i need to use regex to break it out?

Thanks

Dan

Tags (3)
0 Karma

SplunkTrust
SplunkTrust

As far as I have seen, you can directly provide the content in the search and it works with (best practice) or without quotes.
e.g. index=abc http://

index=abc "http://"

0 Karma

Path Finder

surrounding the search string in double quotes should be sufficient (ie. "Server: Apache"). Is that not working?

0 Karma

New Member

The data is in JSOn format, would that make a difference?

0 Karma