I'm having problems when searching for the word NOT in an input Field.
When searching for the text "DO NOT" in the text field i don't get any results. Clicking on the 'View Results' link i noticed splunk converts the input into id="DO" NOT.
How can i escape the Input Properly so the NOT word goes into the field search ( id="DO NOT" ) ? Example code below:
asked 07 Feb '11, 15:20
Splunk only interprets NOT as such when it is fully capitalized.
You can try to quote the string:
You might also consider using eval to lowercase the value:
Alternatively, you can instruct your users to use 'not', 'Not', or something similar.