I have a base search as simple as
And the I have
<query> filter1=A AND filter2=B
This is not working because Splunk adds a pipe between the root and leaf search:
index=w | filter1=A filter2=B
What I wanted to happen is
index=w filter1=A filter2=B
Any ideas how to change this behaviour?
<query> search filter1=A filter2=B
You're not going to be able to remove that pipe. it's either add the filters to the base search or do a |search in the base="root"
View solution in original post
Thank you, that was my suspition. I'll have to live with that.