Splunk Search

Blank Character in string

rafamss
Contributor

Hi,

I have a index configured to get data from a database MSSQL. Well, The data are be obtained with sucess but one column have a string with various blank spaces inside her. When I do my query in Splunk, I don't see the complete string.

Example of content of the String Field: Error in the database. Contact the admin.

I see in Splunk the content of column, in Search , but I don't can find the content by query like a parameter by example.

Example:

index="my index" StringField="Error in the database. Contact the admin."

The result of this query don't return anything. But there are data with this parameter in index.

What I can do ?

Thanks an advance,

RM

0 Karma

rafamss
Contributor

Hi Hiroshi,

Interesting! But in my Search query, it isn't works. See the images below.

In the first image, the search query return my search; In the second image, the left side panel don't shows my search query and in the third image, the search query, I aggregates the search query using the stats command, but in the panel Statistics, doens't show this.

What do you think ?

Image 1
alt text

Image 2
alt text

0 Karma

rafamss
Contributor

I can't insert the third image, sorry.

0 Karma

HiroshiSatoh
Champion

I think that it has failed to field extraction. I think that it needs re-definition of the field.

0 Karma

rafamss
Contributor

I think too. I'll verify this and return. Tks!

0 Karma

HiroshiSatoh
Champion

I can search so, cause you can not find it I think is in the other.

alt text

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...