Splunk Search

Exclude regex results from a search

gnoellbn
Explorer

Hello,

I'm trying to run the following search in order to list all the failed connection.

In our parc we have computers that start with Q and immediately followed by a number. So I know the following search (without the NOT) shows only these computers.

source="WinEventLog:Security" "CategoryString=Ouverture/fermeture" "Type=Failure" Type="Failure Audit" NOT regex host="Q[0-9].*" | stats count by host

But when I add the NOT it doesn't display anything what am I doing wrong ?

Thanks,
Gaetan

Tags (2)
0 Karma
1 Solution

jtrucks
Splunk Employee
Splunk Employee

Do this instead:

source="WinEventLog:Security" "CategoryString=Ouverture/fermeture" "Type=Failure" Type="Failure Audit" | regex host!="Q[0-9].*" | stats count by host

Because regex is a command and the way you have it is: NOT regex AND host="![0-9]"

--
Jesse Trucks
Minister of Magic

View solution in original post

jtrucks
Splunk Employee
Splunk Employee

Do this instead:

source="WinEventLog:Security" "CategoryString=Ouverture/fermeture" "Type=Failure" Type="Failure Audit" | regex host!="Q[0-9].*" | stats count by host

Because regex is a command and the way you have it is: NOT regex AND host="![0-9]"

--
Jesse Trucks
Minister of Magic

gnoellbn
Explorer

Works like a charm! Thanks a lot

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...