<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is the following search that contains &amp;quot;field=&amp;quot; not retuning results unless I use a wildcard? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436049#M124293</link>
    <description>&lt;P&gt;Post some sample data too. This will make it easy to recreate &lt;/P&gt;</description>
    <pubDate>Wed, 17 Oct 2018 13:38:14 GMT</pubDate>
    <dc:creator>skoelpin</dc:creator>
    <dc:date>2018-10-17T13:38:14Z</dc:date>
    <item>
      <title>Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436046#M124290</link>
      <description>&lt;P&gt;Running into a strange issue that I, nor my Splunk admins, can figure out.  We have a filed extraction called "Service" that holds the name of our SOA services.  When I do a search using:&lt;BR /&gt;
&lt;CODE&gt;index=blah Service="examplename"&lt;/CODE&gt; ,  i get no results.&lt;/P&gt;

&lt;P&gt;If I do this, I get results:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=blah Service="*examplename"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;We can not figure out why we have to add the asterisk for it to work.  Even if I do &lt;CODE&gt;index=blah&lt;/CODE&gt; and select a value for Service from the interesting fields, and let Splunk pop that in the search, I get no results.  As soon as I add the *, BAM there are the results.&lt;/P&gt;

&lt;P&gt;I hope someone can help as we are stumped.  This happens on several fields while other extracted fields work fine.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 18:23:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436046#M124290</guid>
      <dc:creator>cjmckenna</dc:creator>
      <dc:date>2018-10-16T18:23:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436047#M124291</link>
      <description>&lt;P&gt;Please post the extraction code.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 20:59:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436047#M124291</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2018-10-16T20:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436048#M124292</link>
      <description>&lt;P&gt;[layer7:sisyslog]&lt;BR /&gt;
EXTRACT-Service = ^(?:[^~\n]*~){2}(?P\w+)&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 13:31:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436048#M124292</guid>
      <dc:creator>cjmckenna</dc:creator>
      <dc:date>2018-10-17T13:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436049#M124293</link>
      <description>&lt;P&gt;Post some sample data too. This will make it easy to recreate &lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 13:38:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436049#M124293</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-10-17T13:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436050#M124294</link>
      <description>&lt;P&gt;Oct 17 09:40:48 info &amp;lt;14&amp;gt;Oct 17 09:40:48 hostname123 SSG[2,651]: [L7Metrics-PRD] INFO com.l7tech.log.custom.si.metrics : -4: ~obfuscateddomainname~obfuscatedservicename~obfuscatedoperationname~&lt;A href="http://obfuscatedWSDLURL/1/%7EobfuscatedWSSid%7E63%7E73%7E"&gt;http://obfuscatedWSDLURL/1/~obfuscatedWSSid~63~73~&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;obfuscatedservicename is where the service name would be and what the extraction is pulling out.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 13:48:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436050#M124294</guid>
      <dc:creator>cjmckenna</dc:creator>
      <dc:date>2018-10-17T13:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436051#M124295</link>
      <description>&lt;P&gt;That regex has a lot of steps and could be refactored.. &lt;/P&gt;

&lt;P&gt;Try this in your search. Field name will be called &lt;CODE&gt;servicename&lt;/CODE&gt;. If this works then you could save this as a search time extraction&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;| rex ^(?:[^~\n]*~){2}(?&amp;lt;servicename&amp;gt;\w+)&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 13:55:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436051#M124295</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-10-17T13:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436052#M124296</link>
      <description>&lt;P&gt;The extraction is working fine.  Please see my original post.  In "Interesting Fields" Service is there and has a list of values.  The issue is whan we do Service="something" we get no results.  Service="*something" does.&lt;/P&gt;

&lt;P&gt;We will look at cleaning up the regex but for now its actually extracting data&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 14:06:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436052#M124296</guid>
      <dc:creator>cjmckenna</dc:creator>
      <dc:date>2018-10-17T14:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436053#M124297</link>
      <description>&lt;P&gt;Yes, I'm thinking it has something to do with your extraction. Keep it simple &lt;/P&gt;

&lt;P&gt;Use the extraction I provided you and save it as a search time extraction so it appears in &lt;CODE&gt;interesting fields&lt;/CODE&gt; without having to explicitly call the rex command. Also, please accept/upvote the answer since it helped solved your problem &lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 14:19:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436053#M124297</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-10-17T14:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436054#M124298</link>
      <description>&lt;P&gt;it has not helped my issue.  Cant upvote something that is not a solution&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 14:22:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436054#M124298</guid>
      <dc:creator>cjmckenna</dc:creator>
      <dc:date>2018-10-17T14:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436055#M124299</link>
      <description>&lt;P&gt;You just said this worked as expected...  Why waste time fixing a poorly written regular expression when I just provided you with a working solution? Your logic doesn't make sense.. &lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 14:25:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436055#M124299</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-10-17T14:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436056#M124300</link>
      <description>&lt;P&gt;No... the EXISTING extraction is working fine.  We see the service names listed in "Service" the "Interesting Fields" with the existing extraction.  The problem is when that field is used in a search we always have to add an *&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 15:05:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436056#M124300</guid>
      <dc:creator>cjmckenna</dc:creator>
      <dc:date>2018-10-17T15:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436057#M124301</link>
      <description>&lt;P&gt;If your existing solution is working fine, then why ask for help on Answers? Your regex is bad and you can prove it by using an inline regex like I provided above to test against.. &lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 15:09:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436057#M124301</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-10-17T15:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436058#M124302</link>
      <description>&lt;P&gt;So help me understand exactly what is wrong in our existing regex when it finds the data and extracts it and it shows up in interesting fields.  Please explain to me why using that data from the existing extraction will not allow us to use index=blah Service="servicename" in a search.  You are saying do this, do that but not providing any insight as to why.&lt;/P&gt;

&lt;P&gt;Maybe its me and I am not explaining that actual issue clear enough&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 15:12:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436058#M124302</guid>
      <dc:creator>cjmckenna</dc:creator>
      <dc:date>2018-10-17T15:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436059#M124303</link>
      <description>&lt;P&gt;I gave you a working solution to test against and told you your regex is bad which is causing the issue. I'm not going to troubleshoot your buggy regex and give you a play by play of why its bad. I gave you the solution and an easy way to test against it. You easily have enough to troubleshoot the problem on your own&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 15:19:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436059#M124303</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-10-17T15:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436060#M124304</link>
      <description>&lt;P&gt;I know what the issue is.  It is explained here:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/tips-and-tricks/cannot-search-based-on-an-extracted-field.html"&gt;https://www.splunk.com/en_us/blog/tips-and-tricks/cannot-search-based-on-an-extracted-field.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Here is the way I understand it.  Splunk automatically indexes word tokens, which are detected using "standard" delimiters like spaces, tabs, commas, etc.&lt;/P&gt;

&lt;P&gt;Here is what most people don't know or understand: even though you specify a search like so (in your example):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=blah Service="examplename"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;What Splunk actually does &lt;EM&gt;initially&lt;/EM&gt; is a search like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=blah "examplename"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Under normal circumstances, this works fine - and it normally returns a "super set" of the results you are looking for.  Then, Splunk refines the results further with a search like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| search Service="examplename"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Which should reduce the data set down to the specific results you are looking for.&lt;/P&gt;

&lt;P&gt;What went wrong here?  Well, your data doesn't have the standard word boundary delimiters Splunk expects.  In your case, there are tilde characters around the word you want to search on, so the &lt;STRONG&gt;"examplename"&lt;/STRONG&gt; string doesn't match, but the &lt;STRONG&gt;"*examplename"&lt;/STRONG&gt; does.&lt;/P&gt;

&lt;P&gt;How can you fix this?  I think you have two choices:&lt;/P&gt;

&lt;P&gt;1) Don't use tildes as delimiters!  Actually, don't use any non-standard delimiters.  But we don't always have control over that, so...&lt;BR /&gt;
2) If you know you have this issue with your data, create a &lt;STRONG&gt;fields.conf&lt;/STRONG&gt; file in the same app that contains your props.conf, and set it like this (NOTE: replace "fieldname" below with the actual fieldname!):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[fieldname]
INDEXED_VALUE = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But don't arbitrarily do this for all of your fields - as it can make your searches less efficient.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 19:49:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436060#M124304</guid>
      <dc:creator>brannonrad</dc:creator>
      <dc:date>2020-01-15T19:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the following search that contains "field=" not retuning results unless I use a wildcard?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436061#M124305</link>
      <description>&lt;P&gt;We too are facing this issue and the only solution we have been able to come up change delimiter before upload.&lt;BR /&gt;
We are using ~ as delimiter in csv file. Using FIELD_NAMES parameter to provide header field names. It is extracting fine but we are not able to search data using extracted field unless we use "*" in search.&lt;BR /&gt;
Were you able to resolve it.&lt;/P&gt;

&lt;P&gt;Adding INDEXED_VALUE = false did not work.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 16:16:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-is-the-following-search-that-contains-quot-field-quot-not/m-p/436061#M124305</guid>
      <dc:creator>payl_chdhry</dc:creator>
      <dc:date>2020-03-12T16:16:44Z</dc:date>
    </item>
  </channel>
</rss>

