By default, which of the following fields would be listed in the fields sidebar under interesting Fields?
The search query index=myindex source=c: mydata. txt NOT error=* specifies three criteria for the events to be returned:
The index must be myindex, which is a user-defined index that contains the data from a specific source or sources.
The source must be c: mydata. txt, which is the name of the file or directory where the data came from.
The error field must not exist in the events, which is indicated by the NOT operator and the wildcard character (*).
The NOT operator negates the following expression, which means that it returns the events that do not match the expression. The wildcard character () matches any value, including an empty value or a null value. Therefore, the expression NOT error=means that the events must not have an error field at all, regardless of its value.
The search query does not use quotation marks around the source value, which means that it is case-sensitive and exact. If there are any variations in the source name, such as capitalization or spacing, they will not match the query.
Reference
Basic searches and search results
Iraida
6 months agoAlise
6 months agoLynda
6 months agoLeonor
7 months agoKimbery
7 months agoAide
7 months agoWilda
7 months agoAlaine
7 months agoDyan
8 months agoVeda
8 months agoAsha
8 months agoRosita
8 months agoMarica
8 months agoYvonne
8 months agoMichell
1 year agoWava
1 year agoArletta
1 year agoDean
11 months agoGlynda
11 months agoLino
12 months agoCarma
1 year agoVannessa
12 months agoLindsey
1 year agoTawna
1 year agoPatrick
1 year agoVeronika
11 months agoEve
12 months agoCarolynn
12 months agoTijuana
1 year agoAnjelica
1 year agoGearldine
1 year agoOdelia
1 year agoMinna
1 year agoArt
1 year agoMinna
1 year ago