Dashboards & Visualizations

Why am I getting error of invalid term on the left hand side?

Robert11
Path Finder

Any advice on how to fix this command? I pulled it from GoSplunk "Show all successful Splunk configurations by user."

This is on Splunk Enterprise. Below is my entered command and I am getting the error:

Comparator '=' has an invalid term on the left hand side: host=object

index=_audit action=edit* info=granted operation!=list host= object=*
| transaction action user operation host maxspan=30s
| stats values(action) as action values(object) as modified_object by _time,operation,user,host
| rename user as modified_by
| table _time action modified_object modified_by

 

Labels (1)
0 Karma
1 Solution

venky1544
Builder

Hi @Robert11 

did you tried host="*"  ?

might not shoe the comparator error 

 

 

 

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Robert11,

I don't know if it's a trascrition error, but there's "host=" without any object.

Ciao.

Giuseppe

Robert11
Path Finder

@gcusello 

Am I to replace "object" with a targeted network/host ID?

0 Karma

venky1544
Builder

Hi @Robert11 

did you tried host="*"  ?

might not shoe the comparator error 

 

 

 

gcusello
SplunkTrust
SplunkTrust

Hi @Robert11,

what is the condition you need?

I don't know what you want to search, I found that you cannot put in a search a condition without a value.

What is the search you're running?

Do you have the error yet?

Ciao.

Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi @Robert11 ,

in other words, the solution I hinted.

Ciao and happy splunking.

Giuseppe

P.S. Karma Points are appreciated by all the Contributors. 😉

Get Updates on the Splunk Community!

Customer Experience | Splunk 2024: New Onboarding Resources

In 2023, we were routinely reminded that the digital world is ever-evolving and susceptible to new ...

Celebrate CX Day with Splunk: Take our interactive quiz, join our LinkedIn Live ...

Today and every day, Splunk celebrates the importance of customer experience throughout our product, ...

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...