Splunk Search

NOT like multiple values

rizwan0683
Path Finder

Looking to exclude certain values for field instance. How can I achieve this?
Propose code (not working)

index=abc sourcetype=xyz IncomingMessage
| rex field=source "/apps/prod/(?<instance>.*)/logs"   
| where NOT LIKE instance IN ("foo", "bar") 
Labels (2)
0 Karma
1 Solution

rizwan0683
Path Finder

thanks, this works
| where NOT LIKE(instance, "%foo%") AND NOT LIKE(instance, "%bar%")

View solution in original post

rizwan0683
Path Finder

thanks, this works
| where NOT LIKE(instance, "%foo%") AND NOT LIKE(instance, "%bar%")

to4kawa
Ultra Champion

I see, accept your answers.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...