Splunk Search

Report results to event summary index, why value with hyphen (-) is double quoted?

JykkeDaMan
Path Finder

Isn't hyphen a minor breaker so I'm wondering why the values with hyphen get double quoted when doing summary indexing? This breaks the tstats TERM and PREFIX usage.

Assume I have the following datas:

_timefield1field2
2022-10-05 22:22:22what-notwhatnot

 

Will end up into summary event index with:

10/05/2022 22:22:22, field="what-not", field=whatnot

  What I have missed when populating my summary index?-)

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You need to add the collect_ignore_minor_breakers=true statement to the [collect] stanza in your limits.conf

https://docs.splunk.com/Documentation/Splunk/9.0.1/SearchReference/Collect?ref=hk#The_collect_and_ts... 

0 Karma

JykkeDaMan
Path Finder

But is this only 9.x feature, since I cannot find it from  8.x. I'm still running 8.1.2.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @JykkeDaMan,

hyphen is usually intepretated by Splunk as the sign of the subtraction, so if you want to use it in a field name, you have to use quotes for that field.

For this reason it's always better to use underscore instead hyphen.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...