Getting Data In

Need Help with Splunk API call and NOT IN operator

zqureshi
New Member

Hello All, I am having issues incorporating the below condition with Splunk API.

items.data.fed_id != \"\" OR items.institution_id != \"\"

I am getting no results and no errors in the results via Splunk API.

I am getting results through the Splunk UI.

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@zqureshi

Please share your sample code and event?

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 3)

Welcome back to Splunk Classroom Chronicles, our ongoing blog series that pulls back the curtain on Splunk ...

Operationalizing TDIR: Building a More Resilient, Scalable SOC

Optimizing SOC workflows with a unified, risk-based approach to Threat Detection, Investigation, and Response ...

Almost Too Eventful Assurance: Part 1

Modern IT and Network teams still struggle with too many alerts and isolating issues before they are notified. ...