Dashboards & Visualizations

Why am I getting error of invalid term on the left hand side?

Robert11
Path Finder

Any advice on how to fix this command? I pulled it from GoSplunk "Show all successful Splunk configurations by user."

This is on Splunk Enterprise. Below is my entered command and I am getting the error:

Comparator '=' has an invalid term on the left hand side: host=object

index=_audit action=edit* info=granted operation!=list host= object=*
| transaction action user operation host maxspan=30s
| stats values(action) as action values(object) as modified_object by _time,operation,user,host
| rename user as modified_by
| table _time action modified_object modified_by

 

Labels (1)
0 Karma
1 Solution

venky1544
Builder

Hi @Robert11 

did you tried host="*"  ?

might not shoe the comparator error 

 

 

 

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Robert11,

I don't know if it's a trascrition error, but there's "host=" without any object.

Ciao.

Giuseppe

Robert11
Path Finder

@gcusello 

Am I to replace "object" with a targeted network/host ID?

0 Karma

venky1544
Builder

Hi @Robert11 

did you tried host="*"  ?

might not shoe the comparator error 

 

 

 

gcusello
SplunkTrust
SplunkTrust

Hi @Robert11,

what is the condition you need?

I don't know what you want to search, I found that you cannot put in a search a condition without a value.

What is the search you're running?

Do you have the error yet?

Ciao.

Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi @Robert11 ,

in other words, the solution I hinted.

Ciao and happy splunking.

Giuseppe

P.S. Karma Points are appreciated by all the Contributors. 😉

Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...