Splunk Enterprise

Why Interesting field Showing values count when i click its showing 0 events and if i use * then its work?

abhishekdubey00
Engager

Interesting field Showing values count when I click its get automatically added search  its showing 0 events and if i use * then its work if i search for particular string then its showing 0 events

 

index=abc 

 Index=abdc cluster_name="abc"   (not working)
 Index=abdc cluster_name="*"      Showing Result 

Labels (2)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

when you are using cluster_name="*" are you getting the "abc" in a result set or not?

If yes then the normal situation is that your data and tokenisation for it has some "issue/challenge".  There could be some ways to fix it with conf files based on what is actually reason for that.

When you are searching it by cluster_name = "*abc" or with another time cluster_name = "abc*" did those works?

You should also look the raw event how it's on index and how it's is tokenised.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...