- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have a splunk query which returns these 2 set of events.
1) domain_name="abc"
microservice_name="test"
message=[WEB] ERROR RESPONSE : NO_DOCUMENTS_FOUND ->
2) domain_name="abc"
microservice_name="test"
message=[WEB] ERROR RESPONSE : GUID_EXPIRED
my vtest.csv lookup looks like below:
domain_name; microservice_name; message
abc; test; NO_DOCUMENTS_FOUND
I am using the below query to exclude 1st set of events. I have created WILDCARD(message) match_type
| lookup vtest message OUTPUT message as exclude_message
| search NOT (exclude_message="*")
But it is not working, and I don't get any fields in "exclude_message" as well. kindly help.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @viku7474 ,
please try this:
<your_search>
NOT [ | inputlookup vtest | rename message AS query | fields quey ]
in this way you perform a full text search in the main search using the lookup's message values.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @viku7474 ,
please try this:
<your_search>
NOT [ | inputlookup vtest | rename message AS query | fields quey ]
in this way you perform a full text search in the main search using the lookup's message values.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Please explain what is meant by "it is not working". What results do you get and how do they not meet your expectations?
The exclude_message field will be null if the lookup fails to find a match.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I want to exclude the first set of events and retain the 2nd set of events, via lookup,
when I use the search NOT condition, it doesn't work as expected.
you're right, exclude_message, there is no field as such is getting created.
