Splunk Search

How to write a search that shows results whenever a particular field does not exist?

alexl1
Path Finder

hi, I want to create a search that shows results whenever a particular field doesn't exist. I tried isnull but it didn't work.

Thanks,

Tags (1)
0 Karma
1 Solution

Ayn
Legend
... NOT yourfield=*

View solution in original post

Ayn
Legend
... NOT yourfield=*

alexl1
Path Finder

thanks xxx

0 Karma
Get Updates on the Splunk Community!

Observability Unveiled: Navigating OpenTelemetry's Framework and Deployment Options

Observability Unveiled: Navigating OpenTelemetry's Framework and Deployment Options A recent Tech Talk, ...

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...