I have the following search
index=collaboration sourcetype="mail-2" Auth | geoip simtaclientip | dedup simtasmtpauthuser | table simtasmtpauthuser simtaclientipcountryname
I would like to exclude the "United States" from the countries returned. Its probably easy but I cannot seem to find a way to do it.
thanks for the help!
... | where field != value
in your case probably something like
where simta_client_ip_country_name != "United States"