I am trying to run this search without success (the search runs however there are 0 results)
sourcetype=dhcplogs description=assign | replace ABC* with ABC in dest | where dest!=ABC
Computers have hostnames in the format "ABC12345678". dest is the field that contains the hostname. I want to exclude these hosts (and other hosts) from the search results.
try something like this:
sourcetype=dhcplogs description=assign | replace ABC* with ABC in dest | where dest!="ABC"
The reason for this is, that where compares the value of two fields or does evaluate boolean expressions. Whereas search can do a wildcard filter like search foo!=bo*.
Hope this helps ...
View solution in original post