Suppose i search for a word that is not indexed by splunk, whether those logs which contain that word will be returned during search?
Hi @simisreedharan,
Yes, if your log contains that keyword it will be returned during the search. Can you elaborate more on your requirement or use case?
Thank You!
Thanks for the reply. I just started learning splunk. So this question arose in my mind. So thought of asking.
Hi @simisreedharan,
Could you please clarify your question ?
If data is not indexed by Splunk you cannot search it. If you mean to ask about searching for a word that is not extracted as a field then the answer is yes it is possible. You simply run your search as follows :
index=yourIndex "yourWordHere"
That will return any events that contain the word you are searching for.
Cheers,
David
Thanks for the answer.
you're most welcome ! please accept if it helped 😉