Is there a way to show events only if they do not contain a specified field. E.g. 40% of my selected events contain a field named Action. I need to access the 60% of events that do not contain the Action field.
Simply add this to your search:
NOT Action="*"
Here is some helpful related discussion: http://answers.splunk.com/questions/310/how-can-i-search-for-a-missing-field
Simply add this to your search:
NOT Action="*"
Here is some helpful related discussion: http://answers.splunk.com/questions/310/how-can-i-search-for-a-missing-field