<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Interesting behaviour in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575389#M10735</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213179"&gt;@eduardo1989&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Did you check Job Inspector? Maybe we can find something from job inspector logs.&lt;/P&gt;&lt;P&gt;Could you please share search.log for the below search?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=win host=MYHOST sourcetype=mysourcetype&lt;/LI-CODE&gt;</description>
    <pubDate>Thu, 18 Nov 2021 08:20:30 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2021-11-18T08:20:30Z</dc:date>
    <item>
      <title>Interesting behaviour</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575122#M10721</link>
      <description>&lt;P class="lia-align-left"&gt;I have faced a very interesting situation and have no clue what is going wrong.&lt;/P&gt;&lt;P class="lia-align-left"&gt;I have a forwarded info from a particular host and if use a search like this I have all results.&lt;/P&gt;&lt;P class="lia-align-left"&gt;&lt;EM&gt;index=win host=MYHOST&lt;/EM&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;If I use this search it gives no results.&lt;/P&gt;&lt;P class="lia-align-left"&gt;&lt;EM&gt;index=win host=MYHOST sourcetype=mysourcetype&lt;/EM&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;BUT in realtime search it gives me the results!&lt;/P&gt;&lt;P class="lia-align-left"&gt;The setup on the host looks like this for mysourcetype.&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;[mylogsource&lt;/SPAN&gt;&lt;SPAN&gt;]&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;disabled&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;=&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;index&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;= win&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;sourcetype&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;= mysourcetype&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 16 Nov 2021 19:17:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575122#M10721</guid>
      <dc:creator>eduardo1989</dc:creator>
      <dc:date>2021-11-16T19:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting behaviour</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575136#M10722</link>
      <description>&lt;P&gt;If you run this, do you see your sourcetype "mysourcetype" listed? If yes, try clicking on it for drilldown and see how the query is formatted.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=win host=MYHOST | stats count by sourcetype&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 16 Nov 2021 20:14:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575136#M10722</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2021-11-16T20:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting behaviour</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575141#M10725</link>
      <description>&lt;P class="lia-align-left"&gt;It is shown and if I drilldown the query is formatted the same as for the another sourcetype which is shown correctly with the same query.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 20:22:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575141#M10725</guid>
      <dc:creator>eduardo1989</dc:creator>
      <dc:date>2021-11-16T20:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting behaviour</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575144#M10726</link>
      <description>&lt;P&gt;When you do the basic search and it gives you the list of results, what do you have in the left hand field list&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bowesmana_0-1637095139973.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16879i7CBA7ABF39D03792/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bowesmana_0-1637095139973.png" alt="bowesmana_0-1637095139973.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and if you click on sourcetype does that show 'mysourcetype' and if&amp;nbsp; and then click on that do you no longer see any results?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 20:40:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575144#M10726</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-11-16T20:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting behaviour</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575170#M10728</link>
      <description>&lt;P&gt;Yes exactly,&lt;/P&gt;&lt;P&gt;the field is there and the sourcetype is also but when I query it gives no results&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 22:52:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575170#M10728</guid>
      <dc:creator>eduardo1989</dc:creator>
      <dc:date>2021-11-16T22:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting behaviour</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575192#M10729</link>
      <description>&lt;P&gt;Sounds like there are some strange characters in there...&lt;/P&gt;&lt;P&gt;Can you do each of these searches separately&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=win host=MYHOST sourcetype=mysourcetype*
index=win host=MYHOST sourcetype=*mysourcetype
index=win host=MYHOST sourcetype=*mysourcetype*
index=win host=MYHOST sourcetype=*&lt;/LI-CODE&gt;&lt;P&gt;and then also do this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=win host=MYHOST
| stats count by sourcetype
| eval st=":".sourcetype.":"
| eval st_len=len(sourcetype)&lt;/LI-CODE&gt;&lt;P&gt;and ensure that they all make sense - i.e. no extra spaces. What it might be is a trailing space in your config - something rings a bell...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 02:19:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575192#M10729</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-11-17T02:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting behaviour</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575202#M10730</link>
      <description>&lt;P&gt;I do not think so unfortunately,&lt;/P&gt;&lt;PRE&gt;index=win host=MYHOST sourcetype=*&lt;/PRE&gt;&lt;P&gt;This query gives me the results.&lt;/P&gt;&lt;P&gt;Your second query regarding the characters gives me perfect results, there is no space or anything else.&lt;/P&gt;&lt;P&gt;Moreover I checked with eval st=_sourcetype and it was perfectly fine.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 07:10:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575202#M10730</guid>
      <dc:creator>eduardo1989</dc:creator>
      <dc:date>2021-11-17T07:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting behaviour</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575347#M10733</link>
      <description>&lt;P&gt;What about the leading and trailing wildcards after your sourcetype - did they all yield results too, or did some of them not show results?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 22:05:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575347#M10733</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-11-17T22:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting behaviour</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575386#M10734</link>
      <description>&lt;P&gt;Nothing else showed the results. Only the one I mentioned.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 07:58:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575386#M10734</guid>
      <dc:creator>eduardo1989</dc:creator>
      <dc:date>2021-11-18T07:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting behaviour</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575389#M10735</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213179"&gt;@eduardo1989&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Did you check Job Inspector? Maybe we can find something from job inspector logs.&lt;/P&gt;&lt;P&gt;Could you please share search.log for the below search?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=win host=MYHOST sourcetype=mysourcetype&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 18 Nov 2021 08:20:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575389#M10735</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-11-18T08:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting behaviour</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575410#M10737</link>
      <description>&lt;P&gt;Yeah I found out it was a MetaData problem.&lt;/P&gt;&lt;P&gt;I checked the SourceTypes.data file&amp;nbsp; in the actual db folder and my sourcetype was not prefixed with sourcetype:: and after I changed it fixed my problem.&lt;/P&gt;&lt;P&gt;So somehow the data was incorrectly handled.&lt;/P&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 09:56:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Interesting-behaviour/m-p/575410#M10737</guid>
      <dc:creator>eduardo1989</dc:creator>
      <dc:date>2021-11-18T09:56:01Z</dc:date>
    </item>
  </channel>
</rss>

