Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

fields in subsearch not showing all results?

$
0
0
Hi all, I tried to find log entries of same mail using queue id from sendmail log. However, for the same time span, following search gives different results. e.g. Gives all records at all time: source="/tmp/sendmail.txt" from="<userA@my.domain.hk>" | fields qid | reverse Only returns part of the records, with those at earlier time slots are missing: source="/tmp/sendmail.txt" [search source="/tmp/sendmail.txt" from="<userA@my.domain.hk>" | fields qid ]| reverse Would anyone please help? Thanks and rgds, /ST Wong

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>