Splunk Search

After upgrading to 7.0.x searches, using NOT host= filters gives no results

pradeepkumarg
Influencer

After upgrade to 7.0.x searches using NOT host= filters are giving no results with the warning in the job inspector as "The specified search with not match any events"

Is there a known issue and workaround surrounding this?

As simple as below doesn't work

index=_internal NOT host=abc

Thanks!

Pradeep

0 Karma
1 Solution

pradeepkumarg
Influencer

Splunk acknowledged this as a bug introduced in 7.0.2 and exists on all 7.0.x versions. This affects when you use NOT on a field that is part of an autolookup. Will update this thread as I learn more on the bug and the fix.

Bug# - SPL-157848
Workaround - set enable_conditional_expansion to true in limits.conf

This bug doesn't impact 7.1.x versions

View solution in original post

pradeepkumarg
Influencer

Splunk acknowledged this as a bug introduced in 7.0.2 and exists on all 7.0.x versions. This affects when you use NOT on a field that is part of an autolookup. Will update this thread as I learn more on the bug and the fix.

Bug# - SPL-157848
Workaround - set enable_conditional_expansion to true in limits.conf

This bug doesn't impact 7.1.x versions

tiagofbmm
Influencer

Do you change that parameter only in the Search Head?

0 Karma

pradeepkumarg
Influencer

yes.. only search heads

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...