Splunk Search

Filtering on combination of 2 values

jpfrancetic
Path Finder

Hi Splunk Community,

I am currently working with a search but I am trying to filter certain events out. I am trying to remove events with user=unknown and id=123456. When I do | where (id=123456 AND user!="unknown"), it removes both events with an unknown user and events with the id = 123456. I would like to keeps all other events with an unknown user and all other events from 123456 while only dropping events where user is unknown AND id=123456.

Thanks in advance!

Labels (1)
0 Karma
1 Solution

Stefanie
Builder

Try this?

|search NOT ((id=123456 AND user="unknown"))

View solution in original post

Chiranjeev
Explorer

you can try |where !(id=123456 AND user="unknown").

hope it helps ,give a thumbs up if you like the answer

0 Karma

Stefanie
Builder

Try this?

|search NOT ((id=123456 AND user="unknown"))

jpfrancetic
Path Finder

Worked like a charm, thank you!

Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...