Splunk Search

What is the difference between "search terms" and "fully qualified query string"?

abour
Explorer
#SPLUNK_ARG_0 Script name
#SPLUNK_ARG_1 Number of events returned
#SPLUNK_ARG_2 Search terms
#SPLUNK_ARG_3 Fully qualified query string
#SPLUNK_ARG_4 Name of report
#SPLUNK_ARG_5 Trigger reason (for example, "The number of events was greater than 1")
#SPLUNK_ARG_6 Browser URL to view the report
#SPLUNK_ARG_7 Not used for historical reasons
#SPLUNK_ARG_8 File in which the results for this search are stored (contains raw results)

What is the difference between 3 and 2? These seem to be the same for me all the time.

Tags (2)
0 Karma

woodcock
Esteemed Legend

Try calling a macro in your search. When you do, the macro name will show up in #2 but the expanded macro code will be placed in-line for #3. Similar things happen for saved searches, etc. It is similar to what you see in the Job Inspector when you examine normalized search (which is analogous to #3) and compare it to what you had in your search bar (which is analogous to #2).

0 Karma
Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...