Splunk Search

KVStore Field returning Invalid result- How do I fix this?

rjscholl
New Member

Hello.

I have some KVStore collections in our cloud environment.  In some of those collections, there are boolean fields that I want to use with search logic.  Examples are called "curbside.disabled" and "curbside.offered".  I want to be able to say if curbside.offered is true, add 1 to a totalOffered field so I can get a count of all offered items offered and all items disabled.  Then I can do some math on those.  Each time I try to use one of those fields, the search failed.  When I assign a temp field to typeof(curbside.disabled), etc. it returns "invalid".  The kvstores were created in Lookup Editor and lookup definitions are created.  I can see the fields and table them.  I can't use the data in them.  What am I doing wrong?

Labels (1)
0 Karma

rjscholl
New Member

I have it working by putting $ before and after the field name.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...