Hello,
I have field name: let's call it - "foo" and a value I desire to add to my search - "bar".
When I execute a normal query, for example:
index="main" sourcetype="blabla" foo="bar"
it won't find anything, although I know there are many events that have the field foo=bar
Alternatively, when I execute the following query:
index="main" sourcetype="blabla" foo="*bar"
I get the results I want.
What causes the first search, which should work, to fail? Is that encoding issue?
Thanks!
Can you share your events?
Hi buddy, unfortunately not, it's sensitive data. I'm sure people had the same problem. I believe it has to do with encoding...
Sounds like maybe a transforms/props issue.
If you are getting hits with the wildcard, I would believe there is a whitespace issue; (where a leading space or more exists in the value.
Hi! I tried to search with a numerous amouns of spaces, yet it cannot find the value. Using the wildcard works, however.
Maybe you have an idea as to how to confirm that?
thanks!
index="main" sourcetype="blabla"
| rex "foo=\"(?<characters>.*)bar\""
| fields characters