<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Greater and less than in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Greater-and-less-than/m-p/522620#M147371</link>
    <description>Can you switch “ to ‘ as “ means value and ‘ means field. Next what you could try is change search to where.&lt;BR /&gt;r. Ismo</description>
    <pubDate>Fri, 02 Oct 2020 04:46:16 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2020-10-02T04:46:16Z</dc:date>
    <item>
      <title>Greater and less than</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Greater-and-less-than/m-p/522619#M147370</link>
      <description>&lt;P&gt;Hi, I'm trying this search and it seems to be working as i'm not getting anything outside the range.&amp;nbsp; The issue is I've created an event that should get picked up by the below search, so I'm obviously doing something wrong here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| search "fooResponse.bets{}.legs{}.propositionId"&amp;gt;=150000 AND "fooResponse.bets{}.legs{}.propositionId"&amp;lt;=180000&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Steve&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 04:00:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Greater-and-less-than/m-p/522619#M147370</guid>
      <dc:creator>stevelfc</dc:creator>
      <dc:date>2020-10-02T04:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: Greater and less than</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Greater-and-less-than/m-p/522620#M147371</link>
      <description>Can you switch “ to ‘ as “ means value and ‘ means field. Next what you could try is change search to where.&lt;BR /&gt;r. Ismo</description>
      <pubDate>Fri, 02 Oct 2020 04:46:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Greater-and-less-than/m-p/522620#M147371</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-02T04:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Greater and less than</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Greater-and-less-than/m-p/522622#M147372</link>
      <description>&lt;P&gt;i think I've worked out why, some of my numbers are coming in an array, so not getting picked up by the search.&lt;BR /&gt;EDIT: mvexpand worked to search in the array&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 05:28:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Greater-and-less-than/m-p/522622#M147372</guid>
      <dc:creator>stevelfc</dc:creator>
      <dc:date>2020-10-02T05:28:51Z</dc:date>
    </item>
  </channel>
</rss>

