Splunk Search

What is the difference between "search terms" and "fully qualified query string"?

abour
Explorer
#SPLUNK_ARG_0 Script name
#SPLUNK_ARG_1 Number of events returned
#SPLUNK_ARG_2 Search terms
#SPLUNK_ARG_3 Fully qualified query string
#SPLUNK_ARG_4 Name of report
#SPLUNK_ARG_5 Trigger reason (for example, "The number of events was greater than 1")
#SPLUNK_ARG_6 Browser URL to view the report
#SPLUNK_ARG_7 Not used for historical reasons
#SPLUNK_ARG_8 File in which the results for this search are stored (contains raw results)

What is the difference between 3 and 2? These seem to be the same for me all the time.

Tags (2)
0 Karma

woodcock
Esteemed Legend

Try calling a macro in your search. When you do, the macro name will show up in #2 but the expanded macro code will be placed in-line for #3. Similar things happen for saved searches, etc. It is similar to what you see in the Job Inspector when you examine normalized search (which is analogous to #3) and compare it to what you had in your search bar (which is analogous to #2).

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...