Splunk Dev

query not returning resutls

sarit_s
Communicator

Hello
I have  a query that contains some conditions and one of them is "AND NOT eventtype=..."
the eventtype is not configured in our system so it is not supposed to return results.. 

my question is - if the condition is "AND NOT" but the eventtype not configured the query should return results or not ?

 

thanks

Tags (2)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sarit_s,

Yes, query will work and produce results. You will just see a yellow warning indicator on the left of Job that says particular eventtype is not exist or disabled.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sarit_s
Communicator

If im running some query AND NOT eventtype=... there are no results but if i will remove the eventtype=.. part it will return results

0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @sarit_s,

Because of NOT condition, missing eventtype field is ok. That is why search will return results. 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

sarit_s
Communicator

Hey

thanks for your reply. Im not sure I understood 

i have a query that contains eventtype=...
but this specific  eventtype is not configured in our system (all of them are configured in eventtype.conf file). So my question was if i have query that contains eventtype that is not configured but im querying it with NOT

the query should work or not ? 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...