Reporting

Unable to filter based on 2 fields- Help with syntax

POR160893
Builder

Hey, I have a big query and I need to have a command on the query that would filter all  Asset_State!="Development" OR Asset_State!="Pre-Production", bit for ONLY Asset_Environment!="PKI  AND Offline" Status="2".

If tried the following command:
| if( Asset_Environment!="PKI  AND Offline" Status="2".,search NOT (Asset_State!="Development" OR Asset_State!="Pre-Production"))

 

I know the syntax is wrong, can you help ?
Many thanks

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @POR160893,

you canoot insert an if conditon in a search, it's possible to use if only in eval command, but you could use something like this, to adapt to your situation:

if you want to exclude events with Asset_State!="Development" OR Asset_State!="Pre-Production", bit for ONLY Asset_Environment!="PKI  AND Offline" Status="2":

...
| search NOT ((Asset_State!="Development" OR Asset_State!="Pre-Production") Asset_Environment!="PKI Offline_Status=2)

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...