Splunk Search

Search for text in log containing say, "non contact" but not just "contact"

here2infinity
Explorer

I have logs that say both contact and non contact. I would like to distinguish them in a search with the complete "non contact" but eliminate all that just say "contact"

Labels (1)
0 Karma

impurush
Contributor

@here2infinity 
You can use like this directly

<your query> "non contacts" to show the logs only it has the term

<your query> NOT "non contacts" to show the logs only the contacts term has.

I have tested in my splunk and it is working.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...