Splunk Search

field::value vs field=value when doing search

htidore
Path Finder

I have a UF, Indexer, Search Head. My UF accepts UDP packets. I created a field in the UF so that I can identify that the packet go through this particular UF:

_meta = env=env1

I performed two searches:

env=env1
env::env1

The result is different.

What is the difference between field::value and field=value when we do search?
Thanks.

Tags (1)
0 Karma

knielsen
Contributor

If you had the meta field configured correctly on your search head, you should not see a difference.

:: is forcing to treat it as an indexed field, regardless of setting it up correctly in fields.conf. Btw, the syntax in your inputs.conf should also use :: instead of =, but maybe both is possible.

Have a look at this discussion: https://answers.splunk.com/answers/389567/why-is-a-search-for-fields-added-with-meta-in-inpu.html which I found when I was having issues with :: vs =.

Hth,
Kai.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...