Splunk Search

Search fieldsummary values for search keyword


Hello, I have query below and want to search by filterstring from fieldsummary values and return all values which matches filterstring from the results of query below -
index =test environment=ps sourcetype=asp_test requestbody=* requestbody="request-body" | fields requestbody | xmlkv | fieldsummary maxvals=10

0 Karma

Ultra Champion
| search your_search_field="*searchvalue*"

Please remove the asterisk appropriately.

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...