Splunk Enterprise

Why Interesting field Showing values count when i click its showing 0 events and if i use * then its work?

abhishekdubey00
Engager

Interesting field Showing values count when I click its get automatically added search  its showing 0 events and if i use * then its work if i search for particular string then its showing 0 events

 

index=abc 

 Index=abdc cluster_name="abc"   (not working)
 Index=abdc cluster_name="*"      Showing Result 

Labels (2)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

when you are using cluster_name="*" are you getting the "abc" in a result set or not?

If yes then the normal situation is that your data and tokenisation for it has some "issue/challenge".  There could be some ways to fix it with conf files based on what is actually reason for that.

When you are searching it by cluster_name = "*abc" or with another time cluster_name = "abc*" did those works?

You should also look the raw event how it's on index and how it's is tokenised.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Changes to Splunk Instructor-Led Training Completion Criteria

We’re excited to share an update to our instructor-led training program that enhances the learning experience ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

❄️ Welcome the new year with our January lineup of Community Office Hours, Tech Talks, and Webinars! 🎉 ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...