Splunk Search

Exclude results from lookup table in search

tromero3
Path Finder

I have a lookup table with Scheduled Tasks called Scheduled_Tasks, and only one column in it called "Task_Name".  This matches the "TaskName" field in my events.

I need to do a search where I only display results where the TaskName field in events DOES NOT contain a value in the Scheduled_Tasks lookup table.  I've looked at almost every question/answer on this topic and came up with this , however it is not excluding anything I have in the lookup table. What am I Doing wrong? Thank you!

index=myindex EventID=4698 NOT [|inputlookup Scheduled_Tasks | fields Task_Name]

Labels (1)
0 Karma
1 Solution

to4kawa
Ultra Champion

index=myindex EventID=4698 NOT [|inputlookup Scheduled_Tasks |rename   Task_Name as TaskName |  fields TaskName]

 

try rename

View solution in original post

TurboTurtle
Engager

I have been trying to add another column, but it's giving me different condition logic. Let's say I want to also filter it not just on a task name in CSV, but with EventCode included.

TaskNameEventCode
Microsoft Edge4101
Firefox4101

 

I tried this:

AND NOT [ | inputlookup wineventlog_exclusions_v2.csv | rename TaskName as query | fields query, EventCode ]

However it doesn't give me what I want, it converts it to:

(NOT EventCode="4104" OR NOT "Microsoft Edge") (NOT EventCode="4104" OR NOT "Firefox"))

I want this:

AND NOT ((EventCode="4104" AND "Microsoft Edge") OR (EventCode="4104" AND "Firefox"))

0 Karma

to4kawa
Ultra Champion

index=myindex EventID=4698 NOT [|inputlookup Scheduled_Tasks |rename   Task_Name as TaskName |  fields TaskName]

 

try rename

tromero3
Path Finder

That worked! Thank you 🙂

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...