I'm trying to exclude a specific value from my search result, what I'm currently getting is the list of top hosts using this query
sourcetype=akamaisiem | timechart count by httpMessage.host
From my query I'm getting all the hostnames, how do I exclude a specific value from the results?
You can exclude the host before the timechart
sourcetype=akamaisiem 'httpMessage.host' !="unwanted host" | timechart count by httpMessage.host