Dashboards & Visualizations

Why am I getting error of invalid term on the left hand side?

Robert11
Path Finder

Any advice on how to fix this command? I pulled it from GoSplunk "Show all successful Splunk configurations by user."

This is on Splunk Enterprise. Below is my entered command and I am getting the error:

Comparator '=' has an invalid term on the left hand side: host=object

index=_audit action=edit* info=granted operation!=list host= object=*
| transaction action user operation host maxspan=30s
| stats values(action) as action values(object) as modified_object by _time,operation,user,host
| rename user as modified_by
| table _time action modified_object modified_by

 

0 Karma
1 Solution

venky1544
Builder

Hi @Robert11 

did you tried host="*"  ?

might not shoe the comparator error 

 

 

 

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Robert11,

I don't know if it's a trascrition error, but there's "host=" without any object.

Ciao.

Giuseppe

Robert11
Path Finder

@gcusello 

Am I to replace "object" with a targeted network/host ID?

0 Karma

venky1544
Builder

Hi @Robert11 

did you tried host="*"  ?

might not shoe the comparator error 

 

 

 

gcusello
SplunkTrust
SplunkTrust

Hi @Robert11,

what is the condition you need?

I don't know what you want to search, I found that you cannot put in a search a condition without a value.

What is the search you're running?

Do you have the error yet?

Ciao.

Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi @Robert11 ,

in other words, the solution I hinted.

Ciao and happy splunking.

Giuseppe

P.S. Karma Points are appreciated by all the Contributors. 😉

Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...