By default, which of the following fields would be listed in the fields sidebar under interesting Fields?
The search query index=myindex source=c: mydata. txt NOT error=* specifies three criteria for the events to be returned:
The index must be myindex, which is a user-defined index that contains the data from a specific source or sources.
The source must be c: mydata. txt, which is the name of the file or directory where the data came from.
The error field must not exist in the events, which is indicated by the NOT operator and the wildcard character (*).
The NOT operator negates the following expression, which means that it returns the events that do not match the expression. The wildcard character () matches any value, including an empty value or a null value. Therefore, the expression NOT error=means that the events must not have an error field at all, regardless of its value.
The search query does not use quotation marks around the source value, which means that it is case-sensitive and exact. If there are any variations in the source name, such as capitalization or spacing, they will not match the query.
Reference
Basic searches and search results
Iraida
3 months agoAlise
3 months agoLynda
3 months agoLeonor
4 months agoKimbery
4 months agoAide
4 months agoWilda
4 months agoAlaine
4 months agoDyan
5 months agoVeda
5 months agoAsha
5 months agoRosita
5 months agoMarica
5 months agoYvonne
5 months agoMichell
9 months agoWava
10 months agoArletta
10 months agoDean
8 months agoGlynda
8 months agoLino
9 months agoCarma
10 months agoVannessa
9 months agoLindsey
9 months agoTawna
10 months agoPatrick
10 months agoVeronika
8 months agoEve
9 months agoCarolynn
9 months agoTijuana
10 months agoAnjelica
10 months agoGearldine
9 months agoOdelia
10 months agoMinna
11 months agoArt
11 months agoMinna
11 months ago