Splunk Search

Filtering on combination of 2 values

jpfrancetic
Path Finder

Hi Splunk Community,

I am currently working with a search but I am trying to filter certain events out. I am trying to remove events with user=unknown and id=123456. When I do | where (id=123456 AND user!="unknown"), it removes both events with an unknown user and events with the id = 123456. I would like to keeps all other events with an unknown user and all other events from 123456 while only dropping events where user is unknown AND id=123456.

Thanks in advance!

Labels (1)
0 Karma
1 Solution

Stefanie
Builder

Try this?

|search NOT ((id=123456 AND user="unknown"))

View solution in original post

Chiranjeev
Explorer

you can try |where !(id=123456 AND user="unknown").

hope it helps ,give a thumbs up if you like the answer

0 Karma

Stefanie
Builder

Try this?

|search NOT ((id=123456 AND user="unknown"))

jpfrancetic
Path Finder

Worked like a charm, thank you!

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...