Splunk Search

What is the difference between "search terms" and "fully qualified query string"?

abour
Explorer
#SPLUNK_ARG_0 Script name
#SPLUNK_ARG_1 Number of events returned
#SPLUNK_ARG_2 Search terms
#SPLUNK_ARG_3 Fully qualified query string
#SPLUNK_ARG_4 Name of report
#SPLUNK_ARG_5 Trigger reason (for example, "The number of events was greater than 1")
#SPLUNK_ARG_6 Browser URL to view the report
#SPLUNK_ARG_7 Not used for historical reasons
#SPLUNK_ARG_8 File in which the results for this search are stored (contains raw results)

What is the difference between 3 and 2? These seem to be the same for me all the time.

Tags (2)
0 Karma

woodcock
Esteemed Legend

Try calling a macro in your search. When you do, the macro name will show up in #2 but the expanded macro code will be placed in-line for #3. Similar things happen for saved searches, etc. It is similar to what you see in the Job Inspector when you examine normalized search (which is analogous to #3) and compare it to what you had in your search bar (which is analogous to #2).

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...