Every day I do a search that searches this:
I know how to filter for a specific event so, for example, I always run this:
source=wineventlog:* earliest_time=-24h
And every day I get about 25,000 hits, 24,000 of which are of this type:
source=wineventlog:* earliest_time=-24h "Type=Success"
I'd like to filter out the 24,000 successes and instead show me the 1,000 events that are not of "Type=Success" How can I do that?
I don't get what's with all double posting of questions lately. How is this different from http://splunk-base.splunk.com/answers/62964/how-to-filter-by-does-not-equal ?
This is an easy one
source=wineventlog:* earliest_time=-24h NOT "Type=Success"
I figured it would be easy but I was clueless. Thanks, emotz!