Splunk Search

After upgrading to 7.0.x searches, using NOT host= filters gives no results

pradeepkumarg
Influencer

After upgrade to 7.0.x searches using NOT host= filters are giving no results with the warning in the job inspector as "The specified search with not match any events"

Is there a known issue and workaround surrounding this?

As simple as below doesn't work

index=_internal NOT host=abc

Thanks!

Pradeep

0 Karma
1 Solution

pradeepkumarg
Influencer

Splunk acknowledged this as a bug introduced in 7.0.2 and exists on all 7.0.x versions. This affects when you use NOT on a field that is part of an autolookup. Will update this thread as I learn more on the bug and the fix.

Bug# - SPL-157848
Workaround - set enable_conditional_expansion to true in limits.conf

This bug doesn't impact 7.1.x versions

View solution in original post

pradeepkumarg
Influencer

Splunk acknowledged this as a bug introduced in 7.0.2 and exists on all 7.0.x versions. This affects when you use NOT on a field that is part of an autolookup. Will update this thread as I learn more on the bug and the fix.

Bug# - SPL-157848
Workaround - set enable_conditional_expansion to true in limits.conf

This bug doesn't impact 7.1.x versions

tiagofbmm
Influencer

Do you change that parameter only in the Search Head?

0 Karma

pradeepkumarg
Influencer

yes.. only search heads

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...