- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why is Search not working but search for NOT != does work?
KeithH
Path Finder
04-07-2022
03:03 PM
Hi All,
I am doing a very simple search over All Time of:
index=index=orafin sourcetype=ORAFIN2
It returns 26 rows and, as this shows, all have a transaction_type value:
If I then select D it adds that to the search but retuns NO rows:
Oddly if I change the search to a double negative I get my data:
Whats going on?
Hoping to be enlightened,
Keith
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VatsalJagani

SplunkTrust
04-07-2022
10:16 PM
Please refer to my answer here - https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work...
---
Consider accepting/upvoting this answer if it is helpful!!!
