Splunk Search

Unknow command (__f!=v) in search log at job inspector

manuelostertag
Path Finder

Hello,

I've create a search which contains (...(CallerCountry="CN")).

When I take a look in the search log in the job inspector (to getting information about my search), I wonder why Splunk change the original (...(CallerCountry="CN")) to (...(__f!=v OR CallerCountry="CN")). The result of this search is "better" then the result of my original search.

Did anybody knows what __f!=v means? I couldn't find anything about it in the Splunk documentation?

PS: I use Splunk Enterprise 8.0.8

Thanks for your support

Manuel

Labels (1)

ejwade
Contributor

@manuelostertagI'm having the same issue. Any luck with this?

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...