Splunk Cloud Platform

one of the field value showing results which didn't search

senthild
Explorer

one for the search query  from splunk AWS 

index="aws_cloud" | search eventname="value1" OR "value2" OR "value3" 

The above search query is giving the events for the all the above searched one also giving one more value which didn't searched 

eventNameLookupEvents ==> getting this field and value which didn't search 

Labels (2)
0 Karma
1 Solution

dtburrows3
Builder

try this instead

 

 index="aws_cloud" eventName IN ("value1", "value2", "value3") 

 


I believe the format you posted is searching eventName="value1" OR any raw log containing the strings "value2" OR "value3" even if "value2" OR "value3" isn't the actual value of eventName for that particular event.

View solution in original post

dtburrows3
Builder

try this instead

 

 index="aws_cloud" eventName IN ("value1", "value2", "value3") 

 


I believe the format you posted is searching eventName="value1" OR any raw log containing the strings "value2" OR "value3" even if "value2" OR "value3" isn't the actual value of eventName for that particular event.

Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...