Splunk Search

Search results that do not contain a word


I tried for an hour but couldn't find the answer. I need to search my syslogs from a specific host for entries that do not contain the word Interface my current search line is:

sourcetype="cisco_syslog" host=""

I tried

sourcetype="cisco_syslog" host="" | regex _raw(=|!=) [\ )?Interface(\] 

but it doesn't work.

I'm sure I'm close but I am terrible at regular expressions.

Re: Search results that do not contain a word

sourcetype="cisco_syslog" host="" NOT "interface"


