what does "::" do in splunk searches, I tried using it interchangably with "=" and it returned the same results. So is there any specific funstionality of "::"
Hey,
That is getting a common key=value
to LISPY syntax There was something in a .conf presentation:
foo="a"
becomes [foo::a]
in LISPY.
https://conf.splunk.com/files/2017/slides/revealing-the-magic-the-life-cycle-of-a-splunk-search.pdf
more:
https://conf.splunk.com/files/2017/slides/fields-indexed-tokens-and-you.pdf
https://answers.splunk.com/answers/144530/are-there-any-good-lispy-docs-out-there.html
Cheerz, Björn
Hi,
there was already a similar questions. It has to do with the differences between indextime and searchtime field extraction. More inforomation here: https://answers.splunk.com/answers/411019/whats-the-difference-between-hostabc-and-hostabc.html
Greetings
Tom
Hey,
That is getting a common key=value
to LISPY syntax There was something in a .conf presentation:
foo="a"
becomes [foo::a]
in LISPY.
https://conf.splunk.com/files/2017/slides/revealing-the-magic-the-life-cycle-of-a-splunk-search.pdf
more:
https://conf.splunk.com/files/2017/slides/fields-indexed-tokens-and-you.pdf
https://answers.splunk.com/answers/144530/are-there-any-good-lispy-docs-out-there.html
Cheerz, Björn