Getting Data In

Need Help with Splunk API call and NOT IN operator

zqureshi
New Member

Hello All, I am having issues incorporating the below condition with Splunk API.

items.data.fed_id != \"\" OR items.institution_id != \"\"

I am getting no results and no errors in the results via Splunk API.

I am getting results through the Splunk UI.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@zqureshi

Please share your sample code and event?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...