Splunk Search

After upgrading to 7.0.x searches, using NOT host= filters gives no results

pradeepkumarg
Influencer

After upgrade to 7.0.x searches using NOT host= filters are giving no results with the warning in the job inspector as "The specified search with not match any events"

Is there a known issue and workaround surrounding this?

As simple as below doesn't work

index=_internal NOT host=abc

Thanks!

Pradeep

0 Karma
1 Solution

pradeepkumarg
Influencer

Splunk acknowledged this as a bug introduced in 7.0.2 and exists on all 7.0.x versions. This affects when you use NOT on a field that is part of an autolookup. Will update this thread as I learn more on the bug and the fix.

Bug# - SPL-157848
Workaround - set enable_conditional_expansion to true in limits.conf

This bug doesn't impact 7.1.x versions

View solution in original post

pradeepkumarg
Influencer

Splunk acknowledged this as a bug introduced in 7.0.2 and exists on all 7.0.x versions. This affects when you use NOT on a field that is part of an autolookup. Will update this thread as I learn more on the bug and the fix.

Bug# - SPL-157848
Workaround - set enable_conditional_expansion to true in limits.conf

This bug doesn't impact 7.1.x versions

tiagofbmm
Influencer

Do you change that parameter only in the Search Head?

0 Karma

pradeepkumarg
Influencer

yes.. only search heads

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...