Splunk Search

Unknow command (__f!=v) in search log at job inspector

manuelostertag
Path Finder

Hello,

I've create a search which contains (...(CallerCountry="CN")).

When I take a look in the search log in the job inspector (to getting information about my search), I wonder why Splunk change the original (...(CallerCountry="CN")) to (...(__f!=v OR CallerCountry="CN")). The result of this search is "better" then the result of my original search.

Did anybody knows what __f!=v means? I couldn't find anything about it in the Splunk documentation?

PS: I use Splunk Enterprise 8.0.8

Thanks for your support

Manuel

Labels (1)

ejwade
Contributor

@manuelostertagI'm having the same issue. Any luck with this?

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...