<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: query not returning resutls in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/query-not-returning-resutls/m-p/542011#M9701</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/149978"&gt;@sarit_s&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Because of NOT condition, missing eventtype field is ok. That is why search will return results.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Mar 2021 16:46:19 GMT</pubDate>
    <dc:creator>scelikok</dc:creator>
    <dc:date>2021-03-02T16:46:19Z</dc:date>
    <item>
      <title>query not returning resutls</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/query-not-returning-resutls/m-p/541717#M9700</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;I have&amp;nbsp; a query that contains some conditions and one of them is "AND NOT eventtype=..."&lt;BR /&gt;the eventtype is not configured in our system so it is not supposed to return results..&amp;nbsp;&lt;/P&gt;&lt;P&gt;my question is - if the condition is "AND NOT" but the eventtype not configured the query should return results or not ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 09:06:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/query-not-returning-resutls/m-p/541717#M9700</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2021-03-01T09:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: query not returning resutls</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/query-not-returning-resutls/m-p/542011#M9701</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/149978"&gt;@sarit_s&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Because of NOT condition, missing eventtype field is ok. That is why search will return results.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 16:46:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/query-not-returning-resutls/m-p/542011#M9701</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-03-02T16:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: query not returning resutls</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/query-not-returning-resutls/m-p/542012#M9702</link>
      <description>&lt;P&gt;Hey&lt;/P&gt;&lt;P&gt;thanks for your reply. Im not sure I understood&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have a query that contains eventtype=...&lt;BR /&gt;but this specific &amp;nbsp;eventtype is not configured in our system (all of them are configured in eventtype.conf file). So my question was if i have query that contains eventtype that is not configured but im querying it with NOT&lt;/P&gt;&lt;P&gt;the query should work or not ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 16:51:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/query-not-returning-resutls/m-p/542012#M9702</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2021-03-02T16:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: query not returning resutls</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/query-not-returning-resutls/m-p/542251#M9703</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/149978"&gt;@sarit_s&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yes, query will work and produce results. You will just see a yellow warning indicator on the left of Job that says particular eventtype is not exist or disabled.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 20:10:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/query-not-returning-resutls/m-p/542251#M9703</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-03-03T20:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: query not returning resutls</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/query-not-returning-resutls/m-p/542287#M9704</link>
      <description>&lt;P&gt;If im running some query AND NOT eventtype=... there are no results but if i will remove the eventtype=.. part it will return results&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 05:03:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/query-not-returning-resutls/m-p/542287#M9704</guid>
      <dc:creator>sarit_s</dc:creator>
      <dc:date>2021-03-04T05:03:45Z</dc:date>
    </item>
  </channel>
</rss>

