Splunk Search

Search strings which are not starting with ****

kmmanu
New Member

Tthere are logs like below three lines

user name is "fgt56wer"
user name is "****89g4ty5"
user name is "jks4qw"

I want to avoid all lines which starts with user name is "**** from the splunk search result
My expected search output is below :-

user name is "fgt56wer"
user name is "jks4qw"

Can anyone help me to get the regular expression or search query ?

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Try:

... | regex _raw!="user name is \"\*\*\*"
Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...