<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filter events with specific text in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Filter-events-with-specific-text/m-p/51107#M12298</link>
    <description>&lt;P&gt;add the following to your search:&lt;/P&gt;

&lt;P&gt;NOT "Failed to ready header on stream TCP"&lt;/P&gt;

&lt;P&gt;Or if that message is already being extracted in a field, &lt;/P&gt;

&lt;P&gt;NOT myfield="Failed to ready header on stream TCP"&lt;/P&gt;</description>
    <pubDate>Mon, 01 Aug 2011 14:57:59 GMT</pubDate>
    <dc:creator>RicoSuave</dc:creator>
    <dc:date>2011-08-01T14:57:59Z</dc:date>
    <item>
      <title>Filter events with specific text</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-events-with-specific-text/m-p/51106#M12297</link>
      <description>&lt;P&gt;I've already indexed a bunch of syslog data.  However, when I search I'd like to be able to filter out certain events that have the same text in them.  How can I do this?  For example I want to filter out "Failed to ready header on stream TCP" from my search results (see example text below).  Thanks!&lt;/P&gt;

&lt;P&gt;Example:&lt;/P&gt;

&lt;P&gt;Aug  1 10:17:56 10.112.101.103 Aug  1 14:17:57 Hostd: [2011-08-01 14:17:57.724 54B16B90 error 'App'] Failed to read header on stream TCP(local=127.0.0.1:62968, peer=127.0.0.1:0): N7Vmacore15SystemExceptionE(Connection reset by peer)&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2011 14:22:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-events-with-specific-text/m-p/51106#M12297</guid>
      <dc:creator>procha</dc:creator>
      <dc:date>2011-08-01T14:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: Filter events with specific text</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Filter-events-with-specific-text/m-p/51107#M12298</link>
      <description>&lt;P&gt;add the following to your search:&lt;/P&gt;

&lt;P&gt;NOT "Failed to ready header on stream TCP"&lt;/P&gt;

&lt;P&gt;Or if that message is already being extracted in a field, &lt;/P&gt;

&lt;P&gt;NOT myfield="Failed to ready header on stream TCP"&lt;/P&gt;</description>
      <pubDate>Mon, 01 Aug 2011 14:57:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Filter-events-with-specific-text/m-p/51107#M12298</guid>
      <dc:creator>RicoSuave</dc:creator>
      <dc:date>2011-08-01T14:57:59Z</dc:date>
    </item>
  </channel>
</rss>

