What is the result of the following search?
index=myindex source=c: \mydata. txt NOT error=*
The search query index=myindex source=c: \mydata. txt NOT error=* specifies three criteria for the events to be returned:
The index must be myindex, which is a user-defined index that contains the data from a specific source or sources.
The source must be c: \mydata. txt, which is the name of the file or directory where the data came from.
The error field must not exist in the events, which is indicated by the NOT operator and the wildcard character (*).
The NOT operator negates the following expression, which means that it returns the events that do not match the expression. The wildcard character () matches any value, including an empty value or a null value. Therefore, the expression NOT error=means that the events must not have an error field at all, regardless of its value.
The search query does not use quotation marks around the source value, which means that it is case-sensitive and exact. If there are any variations in the source name, such as capitalization or spacing, they will not match the query.
Reference
Basic searches and search results
In the Search and Reporting app, which tab displays timecharts and bar charts?
Explanation/Reference: Reference: https://docs.splunk.com/Documentation/Splunk/8.0.2/Search/Aboutreportingcommands
Maryrose
4 hours agoGlory
14 days agoGlenn
28 days agoSoledad
28 days agoMaryanne
1 months agoLavera
1 months agoGaynell
2 months agoZita
2 months agoElke
2 months agoSamira
2 months agoPa
3 months agoJovita
3 months agoMyra
3 months agoMoon
3 months agoCandida
3 months agoXuan
4 months agoDana
4 months agoDestiny
4 months agoMarkus
4 months agoMitsue
4 months agoHildred
5 months agoMerri
5 months agoArminda
5 months agoAretha
5 months agoCarisa
6 months agoDiego
6 months agoRuth
6 months agoBeckie
7 months agoPage
8 months agoJulieta
8 months agoFletcher
8 months agoMan
9 months agoLouis
11 months ago