I want to create a splunk webhook that sends alerts to teams. With this search I dont want to receive emails in that search. Currently the search I am using is index="audit_log" sourcetype="aws:cloudwatchlogs" source="*" ssh NOT ((undefined)) curl.
That search returns https://outlook. I am currently struggling with not having that return in the search. I dont want to receive emails for the webhook that goes to an outlook webhook using curl. If anyone knows what to search that would really help alot.