Splunk Search

Filtering on combination of 2 values

jpfrancetic
Path Finder

Hi Splunk Community,

I am currently working with a search but I am trying to filter certain events out. I am trying to remove events with user=unknown and id=123456. When I do | where (id=123456 AND user!="unknown"), it removes both events with an unknown user and events with the id = 123456. I would like to keeps all other events with an unknown user and all other events from 123456 while only dropping events where user is unknown AND id=123456.

Thanks in advance!

Labels (1)
0 Karma
1 Solution

Stefanie
Builder

Try this?

|search NOT ((id=123456 AND user="unknown"))

View solution in original post

Chiranjeev
Explorer

you can try |where !(id=123456 AND user="unknown").

hope it helps ,give a thumbs up if you like the answer

0 Karma

Stefanie
Builder

Try this?

|search NOT ((id=123456 AND user="unknown"))

jpfrancetic
Path Finder

Worked like a charm, thank you!

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...