Splunk Dev

query not returning resutls

sarit_s
Communicator

Hello
I have  a query that contains some conditions and one of them is "AND NOT eventtype=..."
the eventtype is not configured in our system so it is not supposed to return results.. 

my question is - if the condition is "AND NOT" but the eventtype not configured the query should return results or not ?

 

thanks

Tags (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sarit_s,

Yes, query will work and produce results. You will just see a yellow warning indicator on the left of Job that says particular eventtype is not exist or disabled.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sarit_s
Communicator

If im running some query AND NOT eventtype=... there are no results but if i will remove the eventtype=.. part it will return results

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sarit_s,

Because of NOT condition, missing eventtype field is ok. That is why search will return results. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sarit_s
Communicator

Hey

thanks for your reply. Im not sure I understood 

i have a query that contains eventtype=...
but this specific  eventtype is not configured in our system (all of them are configured in eventtype.conf file). So my question was if i have query that contains eventtype that is not configured but im querying it with NOT

the query should work or not ? 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...