Splunk Search

Exclude search events for a field containing a specific useragent.

bcherdak
New Member

I am attempting to create a sorted count list of useragents that customers are using to browse my website.

I want to exclude certain results and only show events of unknown agents,bots,vulnerability scanners.

Currently I am using the string

index = UV | where NOT like(ad_UserAgent,"%Mozilla%") OR like(ad_UserAgent,"%Opera%") | stats count by ad_UserAgent | sort - count

Is there something I am doing wrong that is still showing events that contain Mozilla and Opera?

thank you for the assistance.

0 Karma

dturnbull_splun
Splunk Employee
Splunk Employee

A more straightforward search might be:

index=UV ad_UserAgent!=*Mozilla* ad_UserAgent!=*Opera* | top limit=0 ad_UserAgent

richgalloway
SplunkTrust
SplunkTrust

Looks like you need some parens. Have you tried ... | where NOT (like(ad_UserAgent,"%Mozilla%") OR like(ad_UserAgent,"%Opera%")) | ... ?

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...