Splunk Search

Splunk query exclude keywords

Csingh
Engager

Hi all

i need some help with my splunk query… basically I need to exclude all jobs from output with job name ending in _fw as shown below:

 

 

jobname

Abc_token_fw

def_file_fw

 

 

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @Csingh 

Can you try this,

<your_search_goes_here> jobname!="*_fw"

 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...