Running Splunk Enterprise 7.3
I am using a text input box to get a list of values from the user to exclude from my search.
For example, in my search the user will supply in the text box the following string: smithJA, JohnsonXL, and I will then remove any entries from my results where the field Account_Name matches either of those names.
I can make this work where return values for only those names, but i cannot do the opposite, where i remove events from the results where the name matches any of the listed names.
here is the XML that i am working with (only returns events that return results where Account_Name matches any of the values given):