<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Spl query is not working in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697010#M236841</link>
    <description>&lt;P&gt;If this is in a dashboard, then that $select321$ looks to be a token and if that token has not been set you will get the message you are seeing.&lt;/P&gt;&lt;P&gt;On a separate point, are the double quotes surrounding the SPL or is that your post? Because it looks like it is a macro, but if the double quotes are really surrounding the macro, then it's not a macro, but a string.&lt;/P&gt;&lt;P&gt;Anyway, the token is your problem.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Aug 2024 01:01:17 GMT</pubDate>
    <dc:creator>bowesmana</dc:creator>
    <dc:date>2024-08-22T01:01:17Z</dc:date>
    <item>
      <title>Spl query is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/696999#M236839</link>
      <description>&lt;P&gt;Hi Team&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please advice why the below query is not showing any data&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;" `secrpt-active-users($select321$)`"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 00:02:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/696999#M236839</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2024-08-22T00:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Spl query is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697001#M236840</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1724280699333.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32351i256CA45CE1788D09/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1724280699333.png" alt="jaibalaraman_0-1724280699333.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 22:51:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697001#M236840</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2024-08-21T22:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Spl query is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697010#M236841</link>
      <description>&lt;P&gt;If this is in a dashboard, then that $select321$ looks to be a token and if that token has not been set you will get the message you are seeing.&lt;/P&gt;&lt;P&gt;On a separate point, are the double quotes surrounding the SPL or is that your post? Because it looks like it is a macro, but if the double quotes are really surrounding the macro, then it's not a macro, but a string.&lt;/P&gt;&lt;P&gt;Anyway, the token is your problem.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 01:01:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697010#M236841</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-08-22T01:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: Spl query is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697012#M236843</link>
      <description>&lt;P&gt;Sorry the "" its my post&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 01:08:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697012#M236843</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2024-08-22T01:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: Spl query is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697014#M236844</link>
      <description>&lt;P&gt;When i am trying to expand the macro, i am getting the below error message&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1724288994815.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32352iA88807F35E10F71A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1724288994815.png" alt="jaibalaraman_0-1724288994815.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 01:10:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697014#M236844</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2024-08-22T01:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Spl query is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697016#M236845</link>
      <description>&lt;P&gt;&lt;FONT&gt;When i navigate to check the token, i find the below&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_1-1724289064147.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32353iBD64AD2C80C7F3F0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_1-1724289064147.png" alt="jaibalaraman_1-1724289064147.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;However i am not sure , is token existing or do i need to create new one.&amp;nbsp;&lt;BR /&gt;&lt;FONT&gt;1 - If i want to create a new token how should i map the spl query to this token ??&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 01:12:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697016#M236845</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2024-08-22T01:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: Spl query is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697018#M236847</link>
      <description>&lt;P&gt;Those are different tokens.&lt;/P&gt;&lt;P&gt;Things in your SPL that have $xxx$ are dashboard tokens and are set by logic in the dashboard, either through an input or through some drilldown.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 01:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697018#M236847</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-08-22T01:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Spl query is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697019#M236848</link>
      <description>&lt;P&gt;Is your problem from a search in a dashboard or a raw search in the search bar?&lt;/P&gt;&lt;P&gt;I suspect this is two issues - the first dashboard issue is a token issue and this is missing the ldapfilter command.&lt;/P&gt;&lt;P&gt;Is this your dashboard - if you do not have access to the ldapfilter command then even if you fix the token you make not get your search working.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 01:26:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697019#M236848</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2024-08-22T01:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: Spl query is not working</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697023#M236850</link>
      <description>&lt;P&gt;Problem from dashboard, this dashboard comes with default package of ITSI which i am trying to do reverse engineering fixing the dashboard&lt;/P&gt;&lt;P&gt;How do i fix this issue&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="jaibalaraman_0-1724297166253.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32355i24762D57DF4A3F4D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="jaibalaraman_0-1724297166253.png" alt="jaibalaraman_0-1724297166253.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is&amp;nbsp;&lt;SPAN&gt;ldapfilter command ? and how do i fix the token issue&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 03:26:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Spl-query-is-not-working/m-p/697023#M236850</guid>
      <dc:creator>jaibalaraman</dc:creator>
      <dc:date>2024-08-22T03:26:44Z</dc:date>
    </item>
  </channel>
</rss>

