<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: _meta not getting expected logs to splunk in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/meta-not-getting-expected-logs-to-splunk/m-p/445022#M173164</link>
    <description>&lt;P&gt;i have already set this in fileds.conf&lt;BR /&gt;
[region]&lt;BR /&gt;
INDEXED=true&lt;/P&gt;</description>
    <pubDate>Tue, 05 Feb 2019 04:17:40 GMT</pubDate>
    <dc:creator>rajpalyalla</dc:creator>
    <dc:date>2019-02-05T04:17:40Z</dc:date>
    <item>
      <title>_meta not getting expected logs to splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/meta-not-getting-expected-logs-to-splunk/m-p/445020#M173162</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;we have index "text-index" &lt;BR /&gt;
and region is passed as meta&lt;BR /&gt;
_meta = region::east&lt;BR /&gt;
sourcetype = testlogs&lt;/P&gt;

&lt;P&gt;when i query &lt;BR /&gt;
index="text-index"  sourcetype=testlogs&lt;BR /&gt;&lt;BR /&gt;
i see all the logs displayed.&lt;/P&gt;

&lt;P&gt;when i use index="text-index"  sourcetype=testlogs  region="*" i see all the logs displayed&lt;/P&gt;

&lt;P&gt;but when i use index="text-index"  sourcetype=testlogs  region="east" it will display the logs only which has word east. its supposed list all the like other two queries above. why does it gives me only if words match. please correct me if i'm doing anything wrong&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 21:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/meta-not-getting-expected-logs-to-splunk/m-p/445020#M173162</guid>
      <dc:creator>rajpalyalla</dc:creator>
      <dc:date>2019-02-04T21:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: _meta not getting expected logs to splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/meta-not-getting-expected-logs-to-splunk/m-p/445021#M173163</link>
      <description>&lt;P&gt;You'll need to declare the &lt;CODE&gt;region&lt;/CODE&gt; field as indexed: &lt;A href="https://answers.splunk.com/answers/723488/is-it-possible-to-treat-a-meta-field-as-a-non-inde.html"&gt;https://answers.splunk.com/answers/723488/is-it-possible-to-treat-a-meta-field-as-a-non-inde.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 22:16:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/meta-not-getting-expected-logs-to-splunk/m-p/445021#M173163</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2019-02-04T22:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: _meta not getting expected logs to splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/meta-not-getting-expected-logs-to-splunk/m-p/445022#M173164</link>
      <description>&lt;P&gt;i have already set this in fileds.conf&lt;BR /&gt;
[region]&lt;BR /&gt;
INDEXED=true&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 04:17:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/meta-not-getting-expected-logs-to-splunk/m-p/445022#M173164</guid>
      <dc:creator>rajpalyalla</dc:creator>
      <dc:date>2019-02-05T04:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: _meta not getting expected logs to splunk</title>
      <link>https://community.splunk.com/t5/Splunk-Search/meta-not-getting-expected-logs-to-splunk/m-p/445023#M173165</link>
      <description>&lt;P&gt;any other suggestions please?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Feb 2019 15:08:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/meta-not-getting-expected-logs-to-splunk/m-p/445023#M173165</guid>
      <dc:creator>rajpalyalla</dc:creator>
      <dc:date>2019-02-12T15:08:38Z</dc:date>
    </item>
  </channel>
</rss>

