Splunk Dev

query not returning resutls

sarit_s
Communicator

Hello
I have  a query that contains some conditions and one of them is "AND NOT eventtype=..."
the eventtype is not configured in our system so it is not supposed to return results.. 

my question is - if the condition is "AND NOT" but the eventtype not configured the query should return results or not ?

 

thanks

Tags (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sarit_s,

Yes, query will work and produce results. You will just see a yellow warning indicator on the left of Job that says particular eventtype is not exist or disabled.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sarit_s
Communicator

If im running some query AND NOT eventtype=... there are no results but if i will remove the eventtype=.. part it will return results

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sarit_s,

Because of NOT condition, missing eventtype field is ok. That is why search will return results. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sarit_s
Communicator

Hey

thanks for your reply. Im not sure I understood 

i have a query that contains eventtype=...
but this specific  eventtype is not configured in our system (all of them are configured in eventtype.conf file). So my question was if i have query that contains eventtype that is not configured but im querying it with NOT

the query should work or not ? 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner

Your Path to AgenticOps: AI Experiences for Every Splunk Practitioner   Join us for a demo-driven look at how ...