Hi all, new user here. I was getting started on the tutorial and using the start searching page that came up after adding the data successfully I'm seeing behaviour I don't understand. The search index="splunktutorial" source="tutorialdata.zip:*" "categoryid=sports" returns results but index="splunktutorial" source="tutorialdata.zip:*" categoryid="sports" or index="splunktutorial" source="tutorialdata.zip:*" categoryid=sports don't return results. To be more confusing I added the condition action=purchase to the search that returned results and it worked as expected to return results where the action was "purchase". https://docs.splunk.com/Documentation/SCS/current/Search/Quotations The splunk documentation for quotation says all string literals must be in double quotes but gives no examples where the field has to be included. Both categoryid and action are classified as strings. Any help understanding what is going on would be appreciated.
... View more