<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic tag=usb in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/tag-usb/m-p/541552#M4934</link>
    <description>&lt;P&gt;So when searching tag=usb, I get an message telling me : "&lt;SPAN&gt;The term 'usb*:' contains a wildcard in the middle of a word or string. This might cause inconsistent results if the characters that the wildcard represents include punctuation", but i did not add the wildard there myself.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;So anyone has any idea where this comes from. One of the things I could think of this comes from an add-on, somewhere..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;While investigating this a little bit more I also see funky errors when searching tag=* for instance.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Feb 2021 16:45:29 GMT</pubDate>
    <dc:creator>hendriks</dc:creator>
    <dc:date>2021-02-26T16:45:29Z</dc:date>
    <item>
      <title>tag=usb</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tag-usb/m-p/541552#M4934</link>
      <description>&lt;P&gt;So when searching tag=usb, I get an message telling me : "&lt;SPAN&gt;The term 'usb*:' contains a wildcard in the middle of a word or string. This might cause inconsistent results if the characters that the wildcard represents include punctuation", but i did not add the wildard there myself.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;So anyone has any idea where this comes from. One of the things I could think of this comes from an add-on, somewhere..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;While investigating this a little bit more I also see funky errors when searching tag=* for instance.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 16:45:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tag-usb/m-p/541552#M4934</guid>
      <dc:creator>hendriks</dc:creator>
      <dc:date>2021-02-26T16:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: tag=usb</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tag-usb/m-p/541555#M4935</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/39021"&gt;@hendriks&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Check in [Settings -- Tag] if there's a tag with "*" inside.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 26 Feb 2021 16:53:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tag-usb/m-p/541555#M4935</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-02-26T16:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: tag=usb</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tag-usb/m-p/541745#M4938</link>
      <description>&lt;P&gt;Ah, thank you, no tags with "*" or any other wildcard inside.&lt;/P&gt;&lt;P&gt;I see there is eventtype=nix_usb that has 3 tags,&amp;nbsp; os, unix, usb, this eventtype comes from&amp;nbsp;&lt;SPAN&gt;Splunk_TA_nix.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So no luck there.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;When I search for tag=* I also get the message that tag=usb* has a wildcard.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 13:02:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tag-usb/m-p/541745#M4938</guid>
      <dc:creator>hendriks</dc:creator>
      <dc:date>2021-03-01T13:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: tag=usb</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/tag-usb/m-p/541746#M4939</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/39021"&gt;@hendriks&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;see in File System in $SPLUNK_HOME/etc/apps/&lt;SPAN&gt;Splunk_TA_nix/default/tags.conf and&amp;nbsp;$SPLUNK_HOME/etc/apps/Splunk_TA_nix/local/tags.conf: sometimes there's an error, you ahould also find the same error in Splunk start-up from console.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if you don't find it, try using the btool command:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$SPLUNK_HOME/bin/splunk cmd btool tag list --debug&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 13:12:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/tag-usb/m-p/541746#M4939</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-03-01T13:12:00Z</dc:date>
    </item>
  </channel>
</rss>

