Loading...
Skip to content
Warren Myers' Merikebi My online archive
  • RSS
  • Facebook
  • Instagram
  • Pinterest
  • Twitter
  • LinkedIn
  • GitHub
  • Telegram
  • Skype

Pages

  • Welcome to Warren Myers’ Merikebi
  • Pocket

Answer by warren for Splunk Streamlined search for specific fields only

Posted on 12 May 2021

Pages

  • Welcome to Warren Myers’ Merikebi

Use OR:

index=ndx sourcetype=srctp (fieldA="myval" OR fieldB="myval" OR fieldC="myval")

Parenthesis added for clarity/readability

from User warren – Stack Overflow https://stackoverflow.com/questions/67495862/splunk-streamlined-search-for-specific-fields-only/67496173#67496173
via IFTTT

merikebi

warrenmyers.com
Taggedstackexchange
by merikebiCategories:blih
  • RSS
  • Skype
© Warren Myers' Merikebi. All rights reserved.
Back to top