Splunk Dev

query not returning resutls

sarit_s
Communicator

Hello
I have  a query that contains some conditions and one of them is "AND NOT eventtype=..."
the eventtype is not configured in our system so it is not supposed to return results.. 

my question is - if the condition is "AND NOT" but the eventtype not configured the query should return results or not ?

 

thanks

Tags (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sarit_s,

Yes, query will work and produce results. You will just see a yellow warning indicator on the left of Job that says particular eventtype is not exist or disabled.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sarit_s
Communicator

If im running some query AND NOT eventtype=... there are no results but if i will remove the eventtype=.. part it will return results

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sarit_s,

Because of NOT condition, missing eventtype field is ok. That is why search will return results. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sarit_s
Communicator

Hey

thanks for your reply. Im not sure I understood 

i have a query that contains eventtype=...
but this specific  eventtype is not configured in our system (all of them are configured in eventtype.conf file). So my question was if i have query that contains eventtype that is not configured but im querying it with NOT

the query should work or not ? 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Federated Search for Dynamic Data Self Storage Is Now Generally Available on Splunk ...

 Splunk is excited to announce the General Availability of Federated Search for Dynamic Data Self Storage ...