Splunk Search

What is the purpose of double-colon syntax in alerts?

mv10
Path Finder

We're doing a review of several thousand alerts. About half of them have this syntax at the end of the initial search terms, where "MyAlertName" is literally the alert name:

 

 

NOT tag::host=MyAlertName

 

 

What does it mean? It doesn't seem to make any difference if it's there or not, but the searches do work with it present, apparently it is syntactically correct.

The docs I've found relating to double-colon syntax don't seem to describe anything like this, and "host" in our environment is always a server name.

Labels (1)
0 Karma
1 Solution

mv10
Path Finder

Thanks!

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...