Splunk Search

how can I search not IN as I was working on a solution building for not including multiple parameters.

Santoshku10
New Member

..........NOT
[search logLevel IN (DEBUG,INFO)]........... it is not giving desired results.

 

how can I search not IN as I was working on a solution building for not including multiple parameters.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

What are the desired results?

When using subsearches, it helps to start with the subsearch by itself.  Run the subsearch with the | format command added to see what the subsearch will return to the main search.  That returned string must be proper SPL and make sense in your environment (fields must exist, etc.).

In the example shown, search logLevel IN (DEBUG,INFO) will return all events from the user's default indexes that contain a logLevel field with a value of "DEBUG" or "INFO".  

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...