I have email entries logged in Splunk. I need to filter out a particular domain of the emails when I list them separately. Like for example, I don't want to see the emails from abc domain (user@abc.com should not be listed in the results). How to go about that?
Is the email extracted as field?? if yes than you can try something like this
index=blah sourcetype=blah youremailfieldname!="*@abc.com" | rest of the search
If its not extracted as field, try something like this
index=blah sourcetype=blah NOT "*@abc.com*" | rest of the search
Is the email extracted as field?? if yes than you can try something like this
index=blah sourcetype=blah youremailfieldname!="*@abc.com" | rest of the search
If its not extracted as field, try something like this
index=blah sourcetype=blah NOT "*@abc.com*" | rest of the search