Splunk Search

Exclude results from lookup table in search

tromero3
Path Finder

I have a lookup table with Scheduled Tasks called Scheduled_Tasks, and only one column in it called "Task_Name".  This matches the "TaskName" field in my events.

I need to do a search where I only display results where the TaskName field in events DOES NOT contain a value in the Scheduled_Tasks lookup table.  I've looked at almost every question/answer on this topic and came up with this , however it is not excluding anything I have in the lookup table. What am I Doing wrong? Thank you!

index=myindex EventID=4698 NOT [|inputlookup Scheduled_Tasks | fields Task_Name]

Labels (1)
0 Karma
1 Solution

to4kawa
Ultra Champion

index=myindex EventID=4698 NOT [|inputlookup Scheduled_Tasks |rename   Task_Name as TaskName |  fields TaskName]

 

try rename

View solution in original post

TurboTurtle
Engager

I have been trying to add another column, but it's giving me different condition logic. Let's say I want to also filter it not just on a task name in CSV, but with EventCode included.

TaskNameEventCode
Microsoft Edge4101
Firefox4101

 

I tried this:

AND NOT [ | inputlookup wineventlog_exclusions_v2.csv | rename TaskName as query | fields query, EventCode ]

However it doesn't give me what I want, it converts it to:

(NOT EventCode="4104" OR NOT "Microsoft Edge") (NOT EventCode="4104" OR NOT "Firefox"))

I want this:

AND NOT ((EventCode="4104" AND "Microsoft Edge") OR (EventCode="4104" AND "Firefox"))

0 Karma

to4kawa
Ultra Champion

index=myindex EventID=4698 NOT [|inputlookup Scheduled_Tasks |rename   Task_Name as TaskName |  fields TaskName]

 

try rename

tromero3
Path Finder

That worked! Thank you 🙂

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...