Splunk Search

Search for text in log containing say, "non contact" but not just "contact"

here2infinity
Explorer

I have logs that say both contact and non contact. I would like to distinguish them in a search with the complete "non contact" but eliminate all that just say "contact"

Labels (1)
0 Karma

impurush
Contributor

@here2infinity 
You can use like this directly

<your query> "non contacts" to show the logs only it has the term

<your query> NOT "non contacts" to show the logs only the contacts term has.

I have tested in my splunk and it is working.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...