In my search result I want to exclude some result that belongs to eventtype, Is it possible ?
my search is
I want to exclude all result from eventtype=procinfo
sourcetype=log_line NOT eventtype=procinfo
View solution in original post
Theres no such thing as a stupid question! Its always quicker to ask if you aren't sure 🙂 Glad it helped
lol I am stupid 🙂
Thanks Drainy Splunk is really very powerful 🙂