Getting Data In
Highlighted

How to filter out results based on 2 values in an event?

Explorer

I'm trying to use a where command to filter a search based on 2 values in an event.

So something like where host!=Domain Controller1 and Message!="Bad Username"

But doing it this way is filtering any events that match either host or Message. How can I filter results based on 2 field values?

0 Karma
Highlighted

Re: How to filter out results based on 2 values in an event?

Motivator

Try using NOT (host=DomainController1 AND Message="Bad Username")

View solution in original post