Splunk Search

No result is showing when i enter the following code .

sw9026
New Member

I am trying to generate report using the following command but it is not showing any result . i just want to make sure is everything right in the code or not . As i was learning splunk from pluralsight.
source="airbnb.csv" index="airbnb" "Review Scores Rating"<70 neighbourhood_group="*" | top limit=5 neighbourhood_group

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Debug SPL by starting with the smallest part of the query and adding bits until it breaks. The last thing added most likely is the problem. In your example, start with index="airbnb" then try source="airbnb.csv" index="airbnb" and so on until you get no results. On the surface, your code looks fine, but we don't know your data so we don't know if you have an incorrect field name, for example.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...