Splunk Search

Search by source name in virtual index does not show results

sdaruna
Explorer

Hi,

i need to get the raw data of file based on source file name. For that i have used below query.

source="xml_file_1.xml" | table _raw

This is giving results only for local indexes, but not the virtual indexes.
I tried below queries as well,

index ="hdfs_index" | search source="xml_file_1.xml" | table _raw
index ="hdfs_index" WHERE source="xml_file_1.xml" | table _raw

But, none has given results.
What went wrong.

Is there a way that i can match the source file name.?

Tags (1)
0 Karma

javiergn
Super Champion

What about the following using a wildcard for your source?

index ="hdfs_index" source="*xml_file_1.xml" | table _raw

Apologies if I'm missing something here.

0 Karma

sdaruna
Explorer

In fact, i missed a point here. The source will be name in virtual indexes will have full path.

I tried below one and worked.

index="hdfs_index" | eval source = replace(source, ".*/", "") | search source="xml_file_0.xml" | table _raw

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...