<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk V 6 error Search query is not fully resolved. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-V-6-error-Search-query-is-not-fully-resolved/m-p/199304#M57702</link>
    <description>&lt;P&gt;Thanks for catching that but it was a copy paste error.  I am still getting the same error message.  I have chopped apart the query and it seems to be something with the "NOT (Logon_Account="&lt;EM&gt;$" OR Logon_account="&lt;/EM&gt;$")" part.  Any ideas?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 15:37:33 GMT</pubDate>
    <dc:creator>ericasmith411</dc:creator>
    <dc:date>2020-09-28T15:37:33Z</dc:date>
    <item>
      <title>Splunk V 6 error Search query is not fully resolved.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-V-6-error-Search-query-is-not-fully-resolved/m-p/199302#M57700</link>
      <description>&lt;P&gt;Good Afternoon,&lt;BR /&gt;
I am new to Splunk and have a query that is working fine in the search but once saved in the Dashboard it errors out with "Search Query is not Fully Resolved."  Anyone have any ideas on what it might be?  Thanks for your help in advance.&lt;/P&gt;

&lt;P&gt;index=main sourcetype=index=main sourcetype="&lt;EM&gt;wineventlog:security"  ("EventCode=4776" AND Keywords="Audit Failure") OR ("EventCode=680" AND "Failure Audit") NOT (Logon_Account="&lt;/EM&gt;$" OR Logon_account="*$")  | eval "User Account" = coalesce(Logon_Account,Logon_account)| top limit=20 host&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:37:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-V-6-error-Search-query-is-not-fully-resolved/m-p/199302#M57700</guid>
      <dc:creator>ericasmith411</dc:creator>
      <dc:date>2020-09-28T15:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk V 6 error Search query is not fully resolved.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-V-6-error-Search-query-is-not-fully-resolved/m-p/199303#M57701</link>
      <description>&lt;P&gt;This in the beginning of the search would give me a headache if I was Splunk:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;index=main sourcetype=index=main&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Change it to:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;index=main sourcetype="wineventlog:security"&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2014 23:07:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-V-6-error-Search-query-is-not-fully-resolved/m-p/199303#M57701</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2014-01-09T23:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk V 6 error Search query is not fully resolved.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-V-6-error-Search-query-is-not-fully-resolved/m-p/199304#M57702</link>
      <description>&lt;P&gt;Thanks for catching that but it was a copy paste error.  I am still getting the same error message.  I have chopped apart the query and it seems to be something with the "NOT (Logon_Account="&lt;EM&gt;$" OR Logon_account="&lt;/EM&gt;$")" part.  Any ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:37:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-V-6-error-Search-query-is-not-fully-resolved/m-p/199304#M57702</guid>
      <dc:creator>ericasmith411</dc:creator>
      <dc:date>2020-09-28T15:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk V 6 error Search query is not fully resolved.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-V-6-error-Search-query-is-not-fully-resolved/m-p/199305#M57703</link>
      <description>&lt;P&gt;Yes, two $ sign make splunk think its a token. see following post,&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/114841/search-query-is-not-fully-resolved-when-using-a-in-a"&gt;http://answers.splunk.com/answers/114841/search-query-is-not-fully-resolved-when-using-a-in-a&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2014 04:03:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-V-6-error-Search-query-is-not-fully-resolved/m-p/199305#M57703</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2014-01-10T04:03:50Z</dc:date>
    </item>
  </channel>
</rss>

