Any advice on how to fix this command? I pulled it from GoSplunk "Show all successful Splunk configurations by user."
This is on Splunk Enterprise. Below is my entered command and I am getting the error:
Comparator '=' has an invalid term on the left hand side: host=object
index=_audit action=edit* info=granted operation!=list host= object=*
| transaction action user operation host maxspan=30s
| stats values(action) as action values(object) as modified_object by _time,operation,user,host
| rename user as modified_by
| table _time action modified_object modified_by
Hi @Robert11,
I don't know if it's a trascrition error, but there's "host=" without any object.
Ciao.
Giuseppe
Am I to replace "object" with a targeted network/host ID?
Hi @Robert11,
what is the condition you need?
I don't know what you want to search, I found that you cannot put in a search a condition without a value.
What is the search you're running?
Do you have the error yet?
Ciao.
Giuseppe
Hi @Robert11 ,
in other words, the solution I hinted.
Ciao and happy splunking.
Giuseppe
P.S. Karma Points are appreciated by all the Contributors. 😉