<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Did my search work or not? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Did-my-search-work-or-not/m-p/581921#M202706</link>
    <description>&lt;P&gt;I've been trying to resolve this since October and not getting traction.&amp;nbsp; Turning to the community for help:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have seemingly contradictory information within the same log line makes me question- do we have an issue or not?&amp;nbsp; &amp;nbsp;On the one hand, i think i do because the history command shows the search is cancelled... and I trust this information.&amp;nbsp; However, there are artifacts in the logs that make me question if the search is fully running (which appears to be true since "fully_completed_search=TRUE".&lt;/SPAN&gt;&lt;SPAN&gt;.. so I am now confused if we have a problem or not.)&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;FONT color="#0000FF"&gt;&lt;SPAN&gt;Why do searches show fully_completed_search=TRUE and has_error_warn=FALSE when the info field (&lt;STRONG&gt;and history command&lt;/STRONG&gt;) show "cancelled" and have a tag of "error"&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT color="#ff0000"&gt;&lt;STRONG&gt;BOTTOM LINE QUESTION: Are my searches are running correctly and returning all results or not?&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;BLOCKQUOTE&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;Sample _audit log search activity that I found - not sure if this gives any usable insight&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Audit:&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN&gt;timestamp=10-01-2021&lt;/SPAN&gt; &lt;SPAN&gt;16:31:40.338&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;user=redacted_user&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;action=search&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;info=canceled&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;search_id=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN&gt;1633105804.108286&lt;/SPAN&gt;&lt;SPAN&gt;', &lt;/SPAN&gt;&lt;FONT color="#339966"&gt;&lt;SPAN&gt;has_error_warn=false&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;FONT color="#339966"&gt;&lt;SPAN&gt;fully_completed_search=true&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;total_run_time=18.13&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;event_count=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;result_count=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;available_count=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;scan_count=133645&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;drop_count=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;exec_time=1633105804&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;api_et=1633104900.000000000&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;api_lt=1633105800.000000000&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;api_index_et=N/A&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;api_index_lt=N/A&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;search_et=1633104900.000000000&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;search_lt=1633105800.000000000&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;is_realtime=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;savedsearch_name=&lt;/SPAN&gt;&lt;SPAN&gt;"", &lt;/SPAN&gt;&lt;SPAN&gt;search_startup_time=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;1270&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN&gt;is_prjob=false&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;acceleration_id=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;98DCBC55-D36C-4671-93CD-1A950D796EC4_search_redacted_user_311d202b50b71a64&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN&gt;app=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;search&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN&gt;provenance=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;N/A&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN&gt;mode=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;historical_batch&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN&gt;workload_pool=standard_perf&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;is_proxied=false&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;searched_buckets=53&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;eliminated_buckets=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;considered_events=133645&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;total_slices=331408&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;decompressed_slices=11305&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;duration.command.search.index=120&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;invocations.command.search.index.bucketcache.hit=53&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;duration.command.search.index.bucketcache.hit=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;invocations.command.search.index.bucketcache.miss=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;duration.command.search.index.bucketcache.miss=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;invocations.command.search.index.bucketcache.error=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;duration.command.search.rawdata=2533&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;invocations.command.search.rawdata.bucketcache.hit=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;duration.command.search.rawdata.bucketcache.hit=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;invocations.command.search.rawdata.bucketcache.miss=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;duration.command.search.rawdata.bucketcache.miss=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;invocations.command.search.rawdata.bucketcache.error=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;roles=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN&gt;redacted&lt;/SPAN&gt;&lt;SPAN&gt;', &lt;/SPAN&gt;&lt;SPAN&gt;search=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN&gt;search&lt;/SPAN&gt; &lt;SPAN&gt;index=oswinsec&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN&gt;EventID=7036&lt;/SPAN&gt; &lt;SPAN&gt;OR&lt;/SPAN&gt; &lt;SPAN&gt;EventID=50&lt;/SPAN&gt; &lt;SPAN&gt;OR&lt;/SPAN&gt; &lt;SPAN&gt;EventID=56&lt;/SPAN&gt; &lt;SPAN&gt;OR&lt;/SPAN&gt; &lt;SPAN&gt;EventID=1000&lt;/SPAN&gt; &lt;SPAN&gt;OR&lt;/SPAN&gt; &lt;SPAN&gt;EventID=1001&lt;/SPAN&gt;&lt;SPAN&gt;) | &lt;/SPAN&gt;&lt;SPAN&gt;eval&lt;/SPAN&gt; &lt;SPAN&gt;my_ts2&lt;/SPAN&gt; &lt;SPAN&gt;=&lt;/SPAN&gt; &lt;SPAN&gt;_time&lt;/SPAN&gt;&lt;SPAN&gt;*&lt;/SPAN&gt;&lt;SPAN&gt;1000&lt;/SPAN&gt;&lt;SPAN&gt; | &lt;/SPAN&gt;&lt;SPAN&gt;eval&lt;/SPAN&gt; &lt;SPAN&gt;indextime=_indextime&lt;/SPAN&gt;&lt;SPAN&gt; |&lt;/SPAN&gt;&lt;SPAN&gt;table&lt;/SPAN&gt; &lt;SPAN&gt;my_ts2&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN&gt;EventID&lt;/SPAN&gt;&lt;SPAN&gt; | &lt;/SPAN&gt;&lt;SPAN&gt;rename&lt;/SPAN&gt; &lt;SPAN&gt;EventID&lt;/SPAN&gt; &lt;SPAN&gt;as&lt;/SPAN&gt; &lt;SPAN&gt;EventCode&lt;/SPAN&gt;&lt;SPAN&gt;']&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 20 Jan 2022 17:20:13 GMT</pubDate>
    <dc:creator>awmorris</dc:creator>
    <dc:date>2022-01-20T17:20:13Z</dc:date>
    <item>
      <title>Did my search work or not?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Did-my-search-work-or-not/m-p/581921#M202706</link>
      <description>&lt;P&gt;I've been trying to resolve this since October and not getting traction.&amp;nbsp; Turning to the community for help:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have seemingly contradictory information within the same log line makes me question- do we have an issue or not?&amp;nbsp; &amp;nbsp;On the one hand, i think i do because the history command shows the search is cancelled... and I trust this information.&amp;nbsp; However, there are artifacts in the logs that make me question if the search is fully running (which appears to be true since "fully_completed_search=TRUE".&lt;/SPAN&gt;&lt;SPAN&gt;.. so I am now confused if we have a problem or not.)&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;FONT color="#0000FF"&gt;&lt;SPAN&gt;Why do searches show fully_completed_search=TRUE and has_error_warn=FALSE when the info field (&lt;STRONG&gt;and history command&lt;/STRONG&gt;) show "cancelled" and have a tag of "error"&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT color="#ff0000"&gt;&lt;STRONG&gt;BOTTOM LINE QUESTION: Are my searches are running correctly and returning all results or not?&amp;nbsp;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&lt;BLOCKQUOTE&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;Sample _audit log search activity that I found - not sure if this gives any usable insight&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Audit:&lt;/SPAN&gt;&lt;SPAN&gt;[&lt;/SPAN&gt;&lt;SPAN&gt;timestamp=10-01-2021&lt;/SPAN&gt; &lt;SPAN&gt;16:31:40.338&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;user=redacted_user&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;action=search&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;&lt;SPAN&gt;info=canceled&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;search_id=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN&gt;1633105804.108286&lt;/SPAN&gt;&lt;SPAN&gt;', &lt;/SPAN&gt;&lt;FONT color="#339966"&gt;&lt;SPAN&gt;has_error_warn=false&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;FONT color="#339966"&gt;&lt;SPAN&gt;fully_completed_search=true&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;total_run_time=18.13&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;event_count=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;result_count=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;available_count=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;scan_count=133645&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;drop_count=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;exec_time=1633105804&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;api_et=1633104900.000000000&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;api_lt=1633105800.000000000&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;api_index_et=N/A&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;api_index_lt=N/A&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;search_et=1633104900.000000000&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;search_lt=1633105800.000000000&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;is_realtime=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;savedsearch_name=&lt;/SPAN&gt;&lt;SPAN&gt;"", &lt;/SPAN&gt;&lt;SPAN&gt;search_startup_time=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;1270&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN&gt;is_prjob=false&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;acceleration_id=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;98DCBC55-D36C-4671-93CD-1A950D796EC4_search_redacted_user_311d202b50b71a64&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN&gt;app=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;search&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN&gt;provenance=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;N/A&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN&gt;mode=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN&gt;historical_batch&lt;/SPAN&gt;&lt;SPAN&gt;", &lt;/SPAN&gt;&lt;SPAN&gt;workload_pool=standard_perf&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;is_proxied=false&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;searched_buckets=53&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;eliminated_buckets=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;considered_events=133645&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;total_slices=331408&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;decompressed_slices=11305&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;duration.command.search.index=120&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;invocations.command.search.index.bucketcache.hit=53&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;duration.command.search.index.bucketcache.hit=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;invocations.command.search.index.bucketcache.miss=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;duration.command.search.index.bucketcache.miss=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;invocations.command.search.index.bucketcache.error=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;duration.command.search.rawdata=2533&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;invocations.command.search.rawdata.bucketcache.hit=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;duration.command.search.rawdata.bucketcache.hit=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;invocations.command.search.rawdata.bucketcache.miss=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;duration.command.search.rawdata.bucketcache.miss=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;invocations.command.search.rawdata.bucketcache.error=0&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN&gt;roles=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN&gt;redacted&lt;/SPAN&gt;&lt;SPAN&gt;', &lt;/SPAN&gt;&lt;SPAN&gt;search=&lt;/SPAN&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;SPAN&gt;search&lt;/SPAN&gt; &lt;SPAN&gt;index=oswinsec&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN&gt;EventID=7036&lt;/SPAN&gt; &lt;SPAN&gt;OR&lt;/SPAN&gt; &lt;SPAN&gt;EventID=50&lt;/SPAN&gt; &lt;SPAN&gt;OR&lt;/SPAN&gt; &lt;SPAN&gt;EventID=56&lt;/SPAN&gt; &lt;SPAN&gt;OR&lt;/SPAN&gt; &lt;SPAN&gt;EventID=1000&lt;/SPAN&gt; &lt;SPAN&gt;OR&lt;/SPAN&gt; &lt;SPAN&gt;EventID=1001&lt;/SPAN&gt;&lt;SPAN&gt;) | &lt;/SPAN&gt;&lt;SPAN&gt;eval&lt;/SPAN&gt; &lt;SPAN&gt;my_ts2&lt;/SPAN&gt; &lt;SPAN&gt;=&lt;/SPAN&gt; &lt;SPAN&gt;_time&lt;/SPAN&gt;&lt;SPAN&gt;*&lt;/SPAN&gt;&lt;SPAN&gt;1000&lt;/SPAN&gt;&lt;SPAN&gt; | &lt;/SPAN&gt;&lt;SPAN&gt;eval&lt;/SPAN&gt; &lt;SPAN&gt;indextime=_indextime&lt;/SPAN&gt;&lt;SPAN&gt; |&lt;/SPAN&gt;&lt;SPAN&gt;table&lt;/SPAN&gt; &lt;SPAN&gt;my_ts2&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN&gt;EventID&lt;/SPAN&gt;&lt;SPAN&gt; | &lt;/SPAN&gt;&lt;SPAN&gt;rename&lt;/SPAN&gt; &lt;SPAN&gt;EventID&lt;/SPAN&gt; &lt;SPAN&gt;as&lt;/SPAN&gt; &lt;SPAN&gt;EventCode&lt;/SPAN&gt;&lt;SPAN&gt;']&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 20 Jan 2022 17:20:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Did-my-search-work-or-not/m-p/581921#M202706</guid>
      <dc:creator>awmorris</dc:creator>
      <dc:date>2022-01-20T17:20:13Z</dc:date>
    </item>
  </channel>
</rss>

