Splunk Search

Skipped search

VijaySrrie
Builder

Hi All,

I am able to see only 4 status, why am I not able to see status=skipped and status = continued

VijaySrrie_0-1725276046695.png

 

Labels (1)
0 Karma

vigneshnarendra
Explorer
  1. Have you included search head captain in your search? I believe only the scheduler node will get the failed logs. If you have included them, follow my next steps.

  2. Do you find them in your logs and they aren't extracted? Append the below SPL to extract them.

| rex field=_raw "status=(?<status>\w+)"

Do you get them when you do stats count on status? 

If not then you have 100% success rate on the searches. 

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...