Hi Splunk Community,
I am currently working with a search but I am trying to filter certain events out. I am trying to remove events with user=unknown and id=123456. When I do | where (id=123456 AND user!="unknown"), it removes both events with an unknown user and events with the id = 123456. I would like to keeps all other events with an unknown user and all other events from 123456 while only dropping events where user is unknown AND id=123456.
Thanks in advance!
you can try |where !(id=123456 AND user="unknown").
hope it helps ,give a thumbs up if you like the answer
Try this?
|search NOT ((id=123456 AND user="unknown"))
Worked like a charm, thank you!