Splunk Search

How to search not equal with multivalued?

Rithekakan
Path Finder

host="SPL-SH-DC" sourcetype="csv" source="****" 
Severity!="Info"
Severity!="low"
Plugin_Name!="SSL Certificate with Wrong Hostname"
Plugin_Name!="Unix Operating System Unsupported Version Detection"
Plugin_Name!="SSL Self-Signed Certificate"
Plugin_Name!="SSL Certificate Cannot Be Trusted"
Port!="8089"
Port!="6502"
| table IP_Address,device_name,Plugin_Name, Severity,model, Protocol, Port, Exploit, Synopsis, Description, Solution, See_Also, CVSS_V2_Base_Score, CVE,Plugin

Thanks for your help!

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
NOT Plugin_Name IN (A,B,C,D)

View solution in original post

Rithekakan
Path Finder

The search result is correct. How ever I am looking for  a short way  writing  not equal  for the same fields and different values. 
Plugin_Name!="A"
Plugin_Name!="B"
Plugin_Name!="C"
Plugin_Name!="D"

I've tried this but it not working.

Plugin_Name !IN (A,B,C,D)

Regards,
Rithekakan
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
NOT Plugin_Name IN (A,B,C,D)

Rithekakan
Path Finder

Hi ITWhisperer,

I got it now. Thanks for your help.

Regards,

Rithekakan 

 
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What you have will search for events which are not equal to the values you are trying to exclude. What else are you asking for?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...