sourcetype=cp_log action!=Drop OR action!=Reject OR action!=dropped
I am socked ,when i am searching with above query in Splunk search for my checkpoint logs .it showing me Drop traffic ,although i have clearly mentioned in query that i don't need Drop traffic(action!=Drop)
Kindly help me on this!
Thanks kamlesh
You have used OR operator for filter , If you want to exclude multiple terms or values you need to use AND operator, like
sourcetype=cp_log (action!=Drop AND action!=Reject AND action!=dropped )
Thanks
KV
▄︻̷̿┻̿═━一 😜
If any of my reply helps you to solve the problem Or gain knowledge, an upvote would be appreciated.