- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
mv10
Path Finder
03-29-2022
12:07 PM
We're doing a review of several thousand alerts. About half of them have this syntax at the end of the initial search terms, where "MyAlertName" is literally the alert name:
NOT tag::host=MyAlertName
What does it mean? It doesn't seem to make any difference if it's there or not, but the searches do work with it present, apparently it is syntactically correct.
The docs I've found relating to double-colon syntax don't seem to describe anything like this, and "host" in our environment is always a server name.
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PickleRick

SplunkTrust
03-29-2022
12:18 PM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PickleRick

SplunkTrust
03-29-2022
12:18 PM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
mv10
Path Finder
03-29-2022
12:57 PM
Thanks!
