<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to drop certain username from search? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-drop-certain-username-from-search/m-p/590783#M205675</link>
    <description>&lt;P&gt;Hi Guys,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am trying to do a search and also at the same time drop certain information from showing up.&lt;BR /&gt;&lt;BR /&gt;As seen from the table below&amp;nbsp; , there is this user [ghjkl-hh123-wer56] that shows up.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Can I know what must I do from the search string such that usernames like the above no longer show up?&lt;BR /&gt;&lt;BR /&gt;Please advise.&lt;/P&gt;
&lt;TABLE width="380"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="211"&gt;username&lt;/TD&gt;
&lt;TD width="169"&gt;hostname&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;user1&lt;/TD&gt;
&lt;TD&gt;host1&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;user2&lt;/TD&gt;
&lt;TD&gt;host2&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ghjkl-hh123-wer56&lt;/TD&gt;
&lt;TD&gt;host3&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ghjkl-hh123-wer56&lt;/TD&gt;
&lt;TD&gt;host4&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;user3&lt;/TD&gt;
&lt;TD&gt;host4&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;Hope this clarifies&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;
&lt;P&gt;regards,&lt;BR /&gt;Alex&lt;/P&gt;</description>
    <pubDate>Fri, 25 Mar 2022 13:55:13 GMT</pubDate>
    <dc:creator>splunknewbie81</dc:creator>
    <dc:date>2022-03-25T13:55:13Z</dc:date>
    <item>
      <title>How to drop certain username from search?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-drop-certain-username-from-search/m-p/590783#M205675</link>
      <description>&lt;P&gt;Hi Guys,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I am trying to do a search and also at the same time drop certain information from showing up.&lt;BR /&gt;&lt;BR /&gt;As seen from the table below&amp;nbsp; , there is this user [ghjkl-hh123-wer56] that shows up.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Can I know what must I do from the search string such that usernames like the above no longer show up?&lt;BR /&gt;&lt;BR /&gt;Please advise.&lt;/P&gt;
&lt;TABLE width="380"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="211"&gt;username&lt;/TD&gt;
&lt;TD width="169"&gt;hostname&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;user1&lt;/TD&gt;
&lt;TD&gt;host1&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;user2&lt;/TD&gt;
&lt;TD&gt;host2&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ghjkl-hh123-wer56&lt;/TD&gt;
&lt;TD&gt;host3&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;ghjkl-hh123-wer56&lt;/TD&gt;
&lt;TD&gt;host4&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;user3&lt;/TD&gt;
&lt;TD&gt;host4&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;BR /&gt;Hope this clarifies&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;
&lt;P&gt;regards,&lt;BR /&gt;Alex&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 13:55:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-drop-certain-username-from-search/m-p/590783#M205675</guid>
      <dc:creator>splunknewbie81</dc:creator>
      <dc:date>2022-03-25T13:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to drop certain username from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-drop-certain-username-from-search/m-p/590785#M205677</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236088"&gt;@splunknewbie81&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can exclude specific username from search using&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;username!="ghjkl-hh123-wer56"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Or exclude &lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;usernames&amp;nbsp; starting with&amp;nbsp;ghjkl&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Use&amp;nbsp;username!="ghjkl*"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Exclude multiple usernames use&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;NOT username IN&amp;nbsp; ("user1" ,"user2")&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 01:59:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-drop-certain-username-from-search/m-p/590785#M205677</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2022-03-25T01:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to drop certain username from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-drop-certain-username-from-search/m-p/590823#M205689</link>
      <description>&lt;P&gt;Just beware that&lt;/P&gt;&lt;PRE&gt;field!=value&lt;/PRE&gt;&lt;P&gt;does not have the same meaning as&lt;/P&gt;&lt;PRE&gt;NOT field=value&lt;/PRE&gt;&lt;P&gt;The first one will match only if there is a field called "field" within an event and its value is not "value".&lt;/P&gt;&lt;P&gt;The second one will match any event in which there is no field called "field" with value "value", which means it will also match events in which there is no field called "field" whatsoever. The first one wouldn't match those events.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 10:10:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-drop-certain-username-from-search/m-p/590823#M205689</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-25T10:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to drop certain username from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-drop-certain-username-from-search/m-p/591164#M205809</link>
      <description>&lt;P&gt;I don't really understand. Can you show me a example please?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 03:47:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-drop-certain-username-from-search/m-p/591164#M205809</guid>
      <dc:creator>splunknewbie81</dc:creator>
      <dc:date>2022-03-29T03:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to drop certain username from search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-drop-certain-username-from-search/m-p/591183#M205815</link>
      <description>&lt;P&gt;Let's assume you have events with two different fields - A and B&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="50%"&gt;&lt;STRONG&gt;A&lt;/STRONG&gt;&lt;/TD&gt;&lt;TD width="50%"&gt;&lt;STRONG&gt;B&lt;/STRONG&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;1&lt;/TD&gt;&lt;TD width="50%"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;2&lt;/TD&gt;&lt;TD width="50%"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;3&lt;/TD&gt;&lt;TD width="50%"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;1&lt;/TD&gt;&lt;TD width="50%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;2&lt;/TD&gt;&lt;TD width="50%"&gt;1&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;3&lt;/TD&gt;&lt;TD width="50%"&gt;2&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;1&lt;/TD&gt;&lt;TD width="50%"&gt;3&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;2&lt;/TD&gt;&lt;TD width="50%"&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="50%"&gt;3&lt;/TD&gt;&lt;TD width="50%"&gt;&lt;P&gt;1&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now if you want to search for&lt;/P&gt;&lt;PRE&gt;A!=1&lt;/PRE&gt;&lt;P&gt;will give you the same results as&lt;/P&gt;&lt;PRE&gt;NOT A=1&lt;/PRE&gt;&lt;P&gt;because the field A has some value in every event.&lt;/P&gt;&lt;P&gt;But if you search for&lt;/P&gt;&lt;PRE&gt;B!=1&lt;/PRE&gt;&lt;P&gt;you will only get events which have a value in B field and that value is different than 1.&lt;/P&gt;&lt;P&gt;So you'll only get as results only those events that have B=2 or B=3.&lt;/P&gt;&lt;P&gt;But if you search for&lt;/P&gt;&lt;PRE&gt;NOT B=1&lt;/PRE&gt;&lt;P&gt;you will get as results all those events in which the B=1 condition is not fulfilled which means that either B=2, B=3 or there is no value for field B at all.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 06:13:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-drop-certain-username-from-search/m-p/591183#M205815</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-29T06:13:31Z</dc:date>
    </item>
  </channel>
</rss>

