Dashboards & Visualizations

Why am I getting error of invalid term on the left hand side?

Robert11
Path Finder

Any advice on how to fix this command? I pulled it from GoSplunk "Show all successful Splunk configurations by user."

This is on Splunk Enterprise. Below is my entered command and I am getting the error:

Comparator '=' has an invalid term on the left hand side: host=object

index=_audit action=edit* info=granted operation!=list host= object=*
| transaction action user operation host maxspan=30s
| stats values(action) as action values(object) as modified_object by _time,operation,user,host
| rename user as modified_by
| table _time action modified_object modified_by

 

0 Karma
1 Solution

venky1544
Builder

Hi @Robert11 

did you tried host="*"  ?

might not shoe the comparator error 

 

 

 

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Robert11,

I don't know if it's a trascrition error, but there's "host=" without any object.

Ciao.

Giuseppe

Robert11
Path Finder

@gcusello 

Am I to replace "object" with a targeted network/host ID?

0 Karma

venky1544
Builder

Hi @Robert11 

did you tried host="*"  ?

might not shoe the comparator error 

 

 

 

gcusello
SplunkTrust
SplunkTrust

Hi @Robert11,

what is the condition you need?

I don't know what you want to search, I found that you cannot put in a search a condition without a value.

What is the search you're running?

Do you have the error yet?

Ciao.

Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi @Robert11 ,

in other words, the solution I hinted.

Ciao and happy splunking.

Giuseppe

P.S. Karma Points are appreciated by all the Contributors. 😉

Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...