Splunk Dev

query not returning resutls

sarit_s
Communicator

Hello
I have  a query that contains some conditions and one of them is "AND NOT eventtype=..."
the eventtype is not configured in our system so it is not supposed to return results.. 

my question is - if the condition is "AND NOT" but the eventtype not configured the query should return results or not ?

 

thanks

Tags (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sarit_s,

Yes, query will work and produce results. You will just see a yellow warning indicator on the left of Job that says particular eventtype is not exist or disabled.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sarit_s
Communicator

If im running some query AND NOT eventtype=... there are no results but if i will remove the eventtype=.. part it will return results

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sarit_s,

Because of NOT condition, missing eventtype field is ok. That is why search will return results. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sarit_s
Communicator

Hey

thanks for your reply. Im not sure I understood 

i have a query that contains eventtype=...
but this specific  eventtype is not configured in our system (all of them are configured in eventtype.conf file). So my question was if i have query that contains eventtype that is not configured but im querying it with NOT

the query should work or not ? 

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...