Splunk Search

Query return Zero Events

manpreetsingh29
Loves-to-Learn Lots

Hi All,

I have query which return all the events for two Hybris pods. When I am using stats it shows the number of events under each pod but when I try to check events for particular pods it shows 0 events are there. 

Attaching Snippet for better understanding.

Splunk.pngSplunk1.png

Please provide your suggestions.

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
One option could be that there is some control or other characters in your pod names. You could try this by adding * to beginning and end of your pod name on your query inside ".
r. Ismo
0 Karma

manpreetsingh29
Loves-to-Learn Lots

Hi @isoutamo ,

I have tried using * at start and end of the string but still it shows zero events.

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Are you sure that this is not a mv field?
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...