Subject: | Pipe symbol causes silent failure |
Trying to send splunk the following query:
sourcetype="tcp-raw" minutesago=15 NOT "gov" NOT "arpa" NOT "localhost" NOT "loopback"
uri_domain="*" | stats count(uri_domain) by uri_domain
and no results are returned. (returns thousands from Splunk web interface).
Truncate from the | (pipe) symbol on and I get data.
obviously I want to use splunk to do aggregation if possible.
Thanks,
Todd