Hi All,
I am doing a very simple search over All Time of:
index=index=orafin sourcetype=ORAFIN2
It returns 26 rows and, as this shows, all have a transaction_type value:
If I then select D it adds that to the search but retuns NO rows:
Oddly if I change the search to a double negative I get my data:
Whats going on?
Hoping to be enlightened,
Keith
Please refer to my answer here - https://community.splunk.com/t5/Splunk-Search/Simple-search-not-working-but-search-for-NOT-does-work...
---
Consider accepting/upvoting this answer if it is helpful!!!