Splunk Search

After upgrading to 7.0.x searches, using NOT host= filters gives no results

pradeepkumarg
Influencer

After upgrade to 7.0.x searches using NOT host= filters are giving no results with the warning in the job inspector as "The specified search with not match any events"

Is there a known issue and workaround surrounding this?

As simple as below doesn't work

index=_internal NOT host=abc

Thanks!

Pradeep

0 Karma
1 Solution

pradeepkumarg
Influencer

Splunk acknowledged this as a bug introduced in 7.0.2 and exists on all 7.0.x versions. This affects when you use NOT on a field that is part of an autolookup. Will update this thread as I learn more on the bug and the fix.

Bug# - SPL-157848
Workaround - set enable_conditional_expansion to true in limits.conf

This bug doesn't impact 7.1.x versions

View solution in original post

pradeepkumarg
Influencer

Splunk acknowledged this as a bug introduced in 7.0.2 and exists on all 7.0.x versions. This affects when you use NOT on a field that is part of an autolookup. Will update this thread as I learn more on the bug and the fix.

Bug# - SPL-157848
Workaround - set enable_conditional_expansion to true in limits.conf

This bug doesn't impact 7.1.x versions

tiagofbmm
Influencer

Do you change that parameter only in the Search Head?

0 Karma

pradeepkumarg
Influencer

yes.. only search heads

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...