I have a dashboard where I am using tokens to filter the results of the individual panels. The use case for the filters are:
Token=anything BUT specific_value
I have the first two tested and working, but can't seem to figure out the best way to account for the 3rd scenario. I have been incorporating the token into my searches by using:
| fillnull value=NULL field (this ensures value will always be equal to something, even when not in an event) | search field=$token$
This works great for scenario 1 and 2 but obviously there is no way (I think?) to leverage field=value when in the last case I want to do the opposite (!=). Is there a better way to leverage the token in my search so I will be able to filter based on all three scenarios? All values, specific value, everything NOT specific value?