Splunk Search

Why using 'in' in a search doesn't yield correct results?

pr0n
Explorer
index="things" AND sourcetype="user_pixel" AND os="*" | search page = "Contact Us" | timechart span=3hr count by os limit=7

Vs

index="things" AND sourcetype="user_pixel" AND os="*" | search page in ("Contact Us") | timechart span=3hr count by os limit=7

The first search gives many results as expected, the second gives nothing.

My ultimate goal is to use a dashboard multi-select to apply this filter. However; first I need to get the "in" function to work correctly. What am I doing wrong?

0 Karma
1 Solution

nickhills
Ultra Champion

Your use of ‘in’ is incorrect

It should be in(page, “Contact Us”,”some other page”)

However, ‘in’ evaluates to true/false, so you can’t use it with search, it’s an evaluation function.

|eval result=in(page, “Contact Us”,”some other page”)

Then you can do:
|where result=true

If my comment helps, please give it a thumbs up!

View solution in original post

spayneort
Contributor

IN should be in caps, and you should not need the "| search" in there.

 index="things" AND sourcetype="user_pixel" AND os="*" page IN ("Contact Us") | timechart span=3hr count by os limit=7

https://docs.splunk.com/Documentation/Splunk/7.2.4/SearchReference/Search#Multiple_field-value_compa...

nickhills
Ultra Champion

Your use of ‘in’ is incorrect

It should be in(page, “Contact Us”,”some other page”)

However, ‘in’ evaluates to true/false, so you can’t use it with search, it’s an evaluation function.

|eval result=in(page, “Contact Us”,”some other page”)

Then you can do:
|where result=true

If my comment helps, please give it a thumbs up!
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...