Getting Data In

Need Help with Splunk API call and NOT IN operator

zqureshi
New Member

Hello All, I am having issues incorporating the below condition with Splunk API.

items.data.fed_id != \"\" OR items.institution_id != \"\"

I am getting no results and no errors in the results via Splunk API.

I am getting results through the Splunk UI.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@zqureshi

Please share your sample code and event?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...