Splunk Search

What is the difference between "search terms" and "fully qualified query string"?

abour
Explorer
#SPLUNK_ARG_0 Script name
#SPLUNK_ARG_1 Number of events returned
#SPLUNK_ARG_2 Search terms
#SPLUNK_ARG_3 Fully qualified query string
#SPLUNK_ARG_4 Name of report
#SPLUNK_ARG_5 Trigger reason (for example, "The number of events was greater than 1")
#SPLUNK_ARG_6 Browser URL to view the report
#SPLUNK_ARG_7 Not used for historical reasons
#SPLUNK_ARG_8 File in which the results for this search are stored (contains raw results)

What is the difference between 3 and 2? These seem to be the same for me all the time.

Tags (2)
0 Karma

woodcock
Esteemed Legend

Try calling a macro in your search. When you do, the macro name will show up in #2 but the expanded macro code will be placed in-line for #3. Similar things happen for saved searches, etc. It is similar to what you see in the Job Inspector when you examine normalized search (which is analogous to #3) and compare it to what you had in your search bar (which is analogous to #2).

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...