<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search filter shortcut for &amp;quot;NOT&amp;quot; in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Search-filter-shortcut-for-quot-NOT-quot/m-p/168888#M48172</link>
    <description>&lt;P&gt;you are right, single click is enough, but it just inserts the term into the search box. what I'm looking for is something that inserts "NOT searchterm" into the search box.&lt;/P&gt;</description>
    <pubDate>Mon, 04 Aug 2014 08:04:02 GMT</pubDate>
    <dc:creator>paterler</dc:creator>
    <dc:date>2014-08-04T08:04:02Z</dc:date>
    <item>
      <title>Search filter shortcut for "NOT"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-filter-shortcut-for-quot-NOT-quot/m-p/168886#M48170</link>
      <description>&lt;P&gt;I know, that I can double click on pretty much anything in the log lines to transfer this term to the search box. But mostly I want to filter down a log file by eliminating certain terms. right now, I double click, go to the search box and write a NOT before the term. Is there a shortcut for this, maybe a modifier (hold ctrl or something like this..)?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2014 07:47:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-filter-shortcut-for-quot-NOT-quot/m-p/168886#M48170</guid>
      <dc:creator>paterler</dc:creator>
      <dc:date>2014-08-04T07:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: Search filter shortcut for "NOT"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-filter-shortcut-for-quot-NOT-quot/m-p/168887#M48171</link>
      <description>&lt;P&gt;Well, yes...you said it yourself, hold ctrl &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Unless I'm misinterpreting you, because from the search view I'm thinking about you only do a single click, not a double click.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2014 07:58:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-filter-shortcut-for-quot-NOT-quot/m-p/168887#M48171</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-08-04T07:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: Search filter shortcut for "NOT"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-filter-shortcut-for-quot-NOT-quot/m-p/168888#M48172</link>
      <description>&lt;P&gt;you are right, single click is enough, but it just inserts the term into the search box. what I'm looking for is something that inserts "NOT searchterm" into the search box.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2014 08:04:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-filter-shortcut-for-quot-NOT-quot/m-p/168888#M48172</guid>
      <dc:creator>paterler</dc:creator>
      <dc:date>2014-08-04T08:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: Search filter shortcut for "NOT"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-filter-shortcut-for-quot-NOT-quot/m-p/168889#M48173</link>
      <description>&lt;P&gt;On a Mac, you can use Option-Click. On Windows, you can use Alt-Click instead.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2014 08:16:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-filter-shortcut-for-quot-NOT-quot/m-p/168889#M48173</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2014-08-04T08:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Search filter shortcut for "NOT"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-filter-shortcut-for-quot-NOT-quot/m-p/168890#M48174</link>
      <description>&lt;P&gt;The answer is..... ALT (on windows) is the modifier to put a NOT in front of the search term.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2014 08:27:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-filter-shortcut-for-quot-NOT-quot/m-p/168890#M48174</guid>
      <dc:creator>paterler</dc:creator>
      <dc:date>2014-08-04T08:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Search filter shortcut for "NOT"</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Search-filter-shortcut-for-quot-NOT-quot/m-p/168891#M48175</link>
      <description>&lt;P&gt;It never occurred to me to even ask, but now that you have I have learnt a helpful shortcut.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2014 11:55:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Search-filter-shortcut-for-quot-NOT-quot/m-p/168891#M48175</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2014-08-04T11:55:44Z</dc:date>
    </item>
  </channel>
</rss>

