Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Incorrect Results from Search on Named Value Pair?

$
0
0

I've got logs in a Named Value Pair Format. When the user runs a search on Status=PR, events like below are returned. This particular log did not have Status returned in the log, but it looks like Splunk is picking up PR from one of the commas defined as part of the CacheKey field.

Any suggestions?

2013-05-31 10:58:19,287 || Thread=52 || System=Coherence || Operation=SetData || HostName=tlpdtmwe || ProcessId=340 || Size=6234 || CorrelationId=1404bb21-5cc7-6051-78d0-4a38990d049a || TimeToLive=-1 || CacheKey=Travelers.PI.Strategic.TM.WebService.Clients.RequestResponseHandlers.DeriveDiscountDescriptionRequestResponseHandler-PA-9-2013-02-08-AF,AT,DT,GS,HO,MC,NC,PF,PR,SD,SS


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>