<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Odd search results where csv values do not seem to be getting indexed correctly in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347982#M63900</link>
    <description>&lt;P&gt;so is the aws app addon installed on the heavy forwarder?  also, since this is a custom log, have you configure the sourcetype properly to parse the logs as expected? &lt;/P&gt;

&lt;P&gt;it would be helpful if you posted the actual log as well as the sourcetype and if you are using props.conf  and/or transforms.conf &lt;/P&gt;

&lt;P&gt;as for the sourcetype, that should be defined on the heavyforwarder as well...&lt;/P&gt;</description>
    <pubDate>Wed, 14 Mar 2018 17:06:54 GMT</pubDate>
    <dc:creator>damiensurat</dc:creator>
    <dc:date>2018-03-14T17:06:54Z</dc:date>
    <item>
      <title>Odd search results where csv values do not seem to be getting indexed correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347976#M63894</link>
      <description>&lt;P&gt;I had a user bring up an issue he was noticing.  There were search results that technically should be returning the exact same results.  One very inefficient and the other, the proper way to search.&lt;/P&gt;

&lt;P&gt;Basically I am able to see returns for a query &lt;BR /&gt;
index=aws "application=agent-softphone-app" NOT application=agent-softphone-app&lt;/P&gt;

&lt;P&gt;These events are coming from a heavy forwarder to a clustered index tier.  It is possible that the indexers are unable to parse all events, so some are being indexed as freeform text?  I am still digging into some ideas regarding the indexers, and only 2 of the indexers are showing event counts inconstantly when running the above query as 2 different searches.&lt;/P&gt;

&lt;P&gt;This environment is not being worked very hard at all.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 18:16:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347976#M63894</guid>
      <dc:creator>Cuyose</dc:creator>
      <dc:date>2018-03-13T18:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: Odd search results where csv values do not seem to be getting indexed correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347977#M63895</link>
      <description>&lt;P&gt;interesting...how are your cvss getting indexed? Are you monitoring a file or is it  a manual process? I had some issues like this when i was monitoring a notepad, the notepad was getting changed (data rows added/data rows modified) and I could see something similar...&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 18:28:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347977#M63895</guid>
      <dc:creator>Sukisen1981</dc:creator>
      <dc:date>2018-03-13T18:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Odd search results where csv values do not seem to be getting indexed correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347978#M63896</link>
      <description>&lt;P&gt;This is coming from an AWS kinesis stream into a heavy forwarder then out to the clustered indexers.  The sourcetype is the same on all indexers, and the 2 indexers seeming unable to find the events using the kv pair, miss about 90% of the time, but can return a few events by only searching vie the kv pair.&lt;/P&gt;

&lt;P&gt;Super wierd&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 18:39:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347978#M63896</guid>
      <dc:creator>Cuyose</dc:creator>
      <dc:date>2018-03-13T18:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Odd search results where csv values do not seem to be getting indexed correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347979#M63897</link>
      <description>&lt;P&gt;what happenes if you search  for just the terms and not the full string:&lt;BR /&gt;
index=aws "application" "agent-softphone-app"&lt;/P&gt;</description>
      <pubDate>Tue, 13 Mar 2018 19:36:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347979#M63897</guid>
      <dc:creator>damiensurat</dc:creator>
      <dc:date>2018-03-13T19:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: Odd search results where csv values do not seem to be getting indexed correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347980#M63898</link>
      <description>&lt;P&gt;index=aws application="agent-softphone-app" = 1661 events&lt;BR /&gt;
index=aws "application" "agent-softphone-app" = 3221 events&lt;BR /&gt;
index=aws "application=agent-softphone-app" =3221 events&lt;/P&gt;

&lt;P&gt;index=aws application=agent-softphone* = 13 events&lt;BR /&gt;
index=aws application=agent-softphone-* = 0 events&lt;/P&gt;

&lt;P&gt;seems something messed up with the -&lt;/P&gt;

&lt;P&gt;All same timeframe&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 16:25:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347980#M63898</guid>
      <dc:creator>Cuyose</dc:creator>
      <dc:date>2018-03-14T16:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: Odd search results where csv values do not seem to be getting indexed correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347981#M63899</link>
      <description>&lt;P&gt;actually, if you put it in quotes ....&lt;BR /&gt;
index=aws application="agent-softphone*"&lt;BR /&gt;
or&lt;BR /&gt;
index=aws application="agent-softphone-*"&lt;/P&gt;

&lt;P&gt;I would expect 1661 results&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:27:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347981#M63899</guid>
      <dc:creator>damiensurat</dc:creator>
      <dc:date>2020-09-29T18:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: Odd search results where csv values do not seem to be getting indexed correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347982#M63900</link>
      <description>&lt;P&gt;so is the aws app addon installed on the heavy forwarder?  also, since this is a custom log, have you configure the sourcetype properly to parse the logs as expected? &lt;/P&gt;

&lt;P&gt;it would be helpful if you posted the actual log as well as the sourcetype and if you are using props.conf  and/or transforms.conf &lt;/P&gt;

&lt;P&gt;as for the sourcetype, that should be defined on the heavyforwarder as well...&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 17:06:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Odd-search-results-where-csv-values-do-not-seem-to-be-getting/m-p/347982#M63900</guid>
      <dc:creator>damiensurat</dc:creator>
      <dc:date>2018-03-14T17:06:54Z</dc:date>
    </item>
  </channel>
</rss>

