Splunk Search

What is the difference between "search terms" and "fully qualified query string"?

abour
Explorer
#SPLUNK_ARG_0 Script name
#SPLUNK_ARG_1 Number of events returned
#SPLUNK_ARG_2 Search terms
#SPLUNK_ARG_3 Fully qualified query string
#SPLUNK_ARG_4 Name of report
#SPLUNK_ARG_5 Trigger reason (for example, "The number of events was greater than 1")
#SPLUNK_ARG_6 Browser URL to view the report
#SPLUNK_ARG_7 Not used for historical reasons
#SPLUNK_ARG_8 File in which the results for this search are stored (contains raw results)

What is the difference between 3 and 2? These seem to be the same for me all the time.

Tags (2)
0 Karma

woodcock
Esteemed Legend

Try calling a macro in your search. When you do, the macro name will show up in #2 but the expanded macro code will be placed in-line for #3. Similar things happen for saved searches, etc. It is similar to what you see in the Job Inspector when you examine normalized search (which is analogous to #3) and compare it to what you had in your search bar (which is analogous to #2).

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...