All Apps and Add-ons

KVStore search issue

jaburke1
Path Finder

Example of issue encountering:

Search one returns a row with all the fields populated

| makeresults count=1
| eval tmp_field1="abc"
| lookup kvstore_name field1 AS tmp_field1

 

Search two returns a row with most of the fields empty (even though it is a search of the same row in the kvstore - just using a different field)

| makeresults count=1
| eval tmp_field2="xyz"
| lookup kvstore_name field2 AS tmp_field2

What could cause the results described above? (any recommendations would be greatly appreciated)

 

 

Labels (1)
Tags (1)
0 Karma

jaburke1
Path Finder

The following search will return values for all the fields

| inputlookup kvstore_name
| where field2="xyz"

 

0 Karma

jaburke1
Path Finder

Any guesses on the cause of this issue?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...