Splunk Search

KVStore Field returning Invalid result- How do I fix this?

rjscholl
New Member

Hello.

I have some KVStore collections in our cloud environment.  In some of those collections, there are boolean fields that I want to use with search logic.  Examples are called "curbside.disabled" and "curbside.offered".  I want to be able to say if curbside.offered is true, add 1 to a totalOffered field so I can get a count of all offered items offered and all items disabled.  Then I can do some math on those.  Each time I try to use one of those fields, the search failed.  When I assign a temp field to typeof(curbside.disabled), etc. it returns "invalid".  The kvstores were created in Lookup Editor and lookup definitions are created.  I can see the fields and table them.  I can't use the data in them.  What am I doing wrong?

Labels (1)
0 Karma

rjscholl
New Member

I have it working by putting $ before and after the field name.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...