Reporting

Unable to filter based on 2 fields- Help with syntax

POR160893
Builder

Hey, I have a big query and I need to have a command on the query that would filter all  Asset_State!="Development" OR Asset_State!="Pre-Production", bit for ONLY Asset_Environment!="PKI  AND Offline" Status="2".

If tried the following command:
| if( Asset_Environment!="PKI  AND Offline" Status="2".,search NOT (Asset_State!="Development" OR Asset_State!="Pre-Production"))

 

I know the syntax is wrong, can you help ?
Many thanks

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @POR160893,

you canoot insert an if conditon in a search, it's possible to use if only in eval command, but you could use something like this, to adapt to your situation:

if you want to exclude events with Asset_State!="Development" OR Asset_State!="Pre-Production", bit for ONLY Asset_Environment!="PKI  AND Offline" Status="2":

...
| search NOT ((Asset_State!="Development" OR Asset_State!="Pre-Production") Asset_Environment!="PKI Offline_Status=2)

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...