Splunk Search

How to search not equal with multivalued?

Rithekakan
Path Finder

host="SPL-SH-DC" sourcetype="csv" source="****" 
Severity!="Info"
Severity!="low"
Plugin_Name!="SSL Certificate with Wrong Hostname"
Plugin_Name!="Unix Operating System Unsupported Version Detection"
Plugin_Name!="SSL Self-Signed Certificate"
Plugin_Name!="SSL Certificate Cannot Be Trusted"
Port!="8089"
Port!="6502"
| table IP_Address,device_name,Plugin_Name, Severity,model, Protocol, Port, Exploit, Synopsis, Description, Solution, See_Also, CVSS_V2_Base_Score, CVE,Plugin

Thanks for your help!

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
NOT Plugin_Name IN (A,B,C,D)

View solution in original post

Rithekakan
Path Finder

The search result is correct. How ever I am looking for  a short way  writing  not equal  for the same fields and different values. 
Plugin_Name!="A"
Plugin_Name!="B"
Plugin_Name!="C"
Plugin_Name!="D"

I've tried this but it not working.

Plugin_Name !IN (A,B,C,D)

Regards,
Rithekakan
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
NOT Plugin_Name IN (A,B,C,D)

Rithekakan
Path Finder

Hi ITWhisperer,

I got it now. Thanks for your help.

Regards,

Rithekakan 

 
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

What you have will search for events which are not equal to the values you are trying to exclude. What else are you asking for?

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...