<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic search function not working properly when comparing lookup value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/search-function-not-working-properly-when-comparing-lookup-value/m-p/84060#M21427</link>
    <description>&lt;P&gt;I'm using the following search using Splunk 4.2.1:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=somesourcetype (tag=Metric AND tag=ResponseTime) NOT tag=Page earliest=-20d | eval upperHost=upper(host) | lookup metrics_lookup Metric as eventtype output ExpectedSLA | lookup cluster_lookup host as upperHost output cluster | search elapsedTime &amp;gt; ExpectedSLA | table cluster, host, eventtype, ExpectedSLA, elapsedTime | sort elapsedTime desc
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Both elapsedTime and ExpectedSLA are numeric, yet the search function is not working properly as it does not return any data.&lt;/P&gt;

&lt;P&gt;search(elapsedTime &amp;lt; ExpectedSLA) returns all rows, even the ones where elapsedTime is greater than ExpectedSLA.&lt;/P&gt;

&lt;P&gt;search(elapsedTime &amp;lt; 200) works as expected, and seach(ExpectedSLA &amp;gt; 200) works as expected; they just don't work together!&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;</description>
    <pubDate>Fri, 30 Sep 2011 14:45:07 GMT</pubDate>
    <dc:creator>johnboldt</dc:creator>
    <dc:date>2011-09-30T14:45:07Z</dc:date>
    <item>
      <title>search function not working properly when comparing lookup value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-function-not-working-properly-when-comparing-lookup-value/m-p/84060#M21427</link>
      <description>&lt;P&gt;I'm using the following search using Splunk 4.2.1:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype=somesourcetype (tag=Metric AND tag=ResponseTime) NOT tag=Page earliest=-20d | eval upperHost=upper(host) | lookup metrics_lookup Metric as eventtype output ExpectedSLA | lookup cluster_lookup host as upperHost output cluster | search elapsedTime &amp;gt; ExpectedSLA | table cluster, host, eventtype, ExpectedSLA, elapsedTime | sort elapsedTime desc
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Both elapsedTime and ExpectedSLA are numeric, yet the search function is not working properly as it does not return any data.&lt;/P&gt;

&lt;P&gt;search(elapsedTime &amp;lt; ExpectedSLA) returns all rows, even the ones where elapsedTime is greater than ExpectedSLA.&lt;/P&gt;

&lt;P&gt;search(elapsedTime &amp;lt; 200) works as expected, and seach(ExpectedSLA &amp;gt; 200) works as expected; they just don't work together!&lt;/P&gt;

&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2011 14:45:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-function-not-working-properly-when-comparing-lookup-value/m-p/84060#M21427</guid>
      <dc:creator>johnboldt</dc:creator>
      <dc:date>2011-09-30T14:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: search function not working properly when comparing lookup value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-function-not-working-properly-when-comparing-lookup-value/m-p/84061#M21428</link>
      <description>&lt;P&gt;Well you should try the 'where' command instead of 'search'.  'where' sees unquoted strings as field names on the right-hand-side of expressions,  whereas 'search' sees them as literals. &lt;/P&gt;

&lt;P&gt;For example: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| search foo=bar 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;will check the foo field against the literal "bar", whereas &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| where foo=bar 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;will check whether the foo field equals the bar field.   Something similar could well be happening with the &amp;gt; operator.   (In effect it would be checking whether the elapsedTime field alphabetized after the string constant "ExpectedSLA".... )&lt;/P&gt;

&lt;P&gt;The other idea is that eventtype is a multivalued field technically (even if there's only one value),  so if you have more than one eventtype this might mean that ExpectedSLA comes out as a multivalued field, and the comparator gets confused. &lt;/P&gt;

&lt;P&gt;maybe try a " | nomv eventtype",   or a "| mvexpand eventtype"  before the lookup?&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2011 01:55:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-function-not-working-properly-when-comparing-lookup-value/m-p/84061#M21428</guid>
      <dc:creator>sideview</dc:creator>
      <dc:date>2011-10-01T01:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: search function not working properly when comparing lookup value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/search-function-not-working-properly-when-comparing-lookup-value/m-p/84062#M21429</link>
      <description>&lt;P&gt;Thanks Nick - using the where command did the trick!&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2011 03:53:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/search-function-not-working-properly-when-comparing-lookup-value/m-p/84062#M21429</guid>
      <dc:creator>johnboldt</dc:creator>
      <dc:date>2011-10-03T03:53:38Z</dc:date>
    </item>
  </channel>
</rss>

