<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Simple search not working but search for NOT != does work. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593231#M206480</link>
    <description>&lt;P&gt;Hi Kamlesh,&lt;/P&gt;&lt;P&gt;Thanks for the suggestion.&amp;nbsp; I ran what you sent but it shows the field values as 1 byte long.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KeithH_0-1649651866044.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19019i0EDD6C1FF8FBA808/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KeithH_0-1649651866044.png" alt="KeithH_0-1649651866044.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So its not htat.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Apr 2022 04:37:54 GMT</pubDate>
    <dc:creator>KeithH</dc:creator>
    <dc:date>2022-04-11T04:37:54Z</dc:date>
    <item>
      <title>Simple search not working but search for NOT != does work.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593034#M206424</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I hope someone can enlighten me with this seemingly simple problem.&lt;/P&gt;&lt;P&gt;I have this very simple search return 32 rows and showing that all events have a transaction_type value.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KeithH_0-1649388935571.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18996i1E59EDEB9F525663/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KeithH_0-1649388935571.png" alt="KeithH_0-1649388935571.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If I click on the D highlighted above I would expect it to show me just the 20 D rows but instead I get:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KeithH_1-1649388994612.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18997i2B862F4D3D053F19/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KeithH_1-1649388994612.png" alt="KeithH_1-1649388994612.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Very weird.&lt;/P&gt;&lt;P&gt;If I change the search to&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=orafin sourcetype=ORAFIN2 NOT transaction_type!=D&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I get what I want:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KeithH_2-1649389196087.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19000i3EEC95D02592E30C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KeithH_2-1649389196087.png" alt="KeithH_2-1649389196087.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Can someone please explain what is happening?&lt;/P&gt;&lt;P&gt;Thanks, Keith&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 03:48:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593034#M206424</guid>
      <dc:creator>KeithH</dc:creator>
      <dc:date>2022-04-08T03:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: Simple search not working but search for NOT != does work.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593035#M206425</link>
      <description>&lt;P&gt;Oh - I am running Enterprise version 8.2.4&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 03:44:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593035#M206425</guid>
      <dc:creator>KeithH</dc:creator>
      <dc:date>2022-04-08T03:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: Simple search not working but search for NOT != does work.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593042#M206426</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229975"&gt;@KeithH&lt;/a&gt;&amp;nbsp;- Splunk is searching "D" in the _raw log (events). But in the event, it's not D as alone and that is the reason it is not working. If this is the case then use the following instead:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=orafin sourcetype=ORAFIN2 transaction_type="D*"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!!!&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 05:01:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593042#M206426</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-04-08T05:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: Simple search not working but search for NOT != does work.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593048#M206430</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229975"&gt;@KeithH&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please make sure there is No trailing space in&amp;nbsp;transaction_type fields? Just execute below search and check the&amp;nbsp;transaction_type_len, it should be 1 for value D.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=orafin sourcetype=ORAFIN2 transaction_type="*"
| eval transaction_type_len = len(transaction_type) | table transaction_type transaction_type_len&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;KV&lt;BR /&gt;&lt;BR /&gt;If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 05:42:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593048#M206430</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2022-04-08T05:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: Simple search not working but search for NOT != does work.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593231#M206480</link>
      <description>&lt;P&gt;Hi Kamlesh,&lt;/P&gt;&lt;P&gt;Thanks for the suggestion.&amp;nbsp; I ran what you sent but it shows the field values as 1 byte long.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KeithH_0-1649651866044.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/19019i0EDD6C1FF8FBA808/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KeithH_0-1649651866044.png" alt="KeithH_0-1649651866044.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So its not htat.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 04:37:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593231#M206480</guid>
      <dc:creator>KeithH</dc:creator>
      <dc:date>2022-04-11T04:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: Simple search not working but search for NOT != does work.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593232#M206481</link>
      <description>&lt;P&gt;Hi Vatsal,&lt;/P&gt;&lt;P&gt;Thanks for that.&amp;nbsp; Your suggestion works.&amp;nbsp; I would have thought that Splunk would search on the field transaction_type which is extracted at search time as a single character field.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does this mean if I want to search on the field value (as opposed to words in the _raw) do I need to extract these at index time?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 04:43:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593232#M206481</guid>
      <dc:creator>KeithH</dc:creator>
      <dc:date>2022-04-11T04:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Simple search not working but search for NOT != does work.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593272#M206494</link>
      <description>&lt;P&gt;You can use index-time extraction if you want better performance.&lt;/P&gt;&lt;P&gt;Just make sure your search syntax will be something like the below:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=orafin sourcetype=ORAFIN2 indexed_transaction_type::D&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-----&lt;BR /&gt;If this was helpful, an upvote would be appreciated!!!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 10:02:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work/m-p/593272#M206494</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-04-11T10:02:57Z</dc:date>
    </item>
  </channel>
</rss>

