..........NOT
[search logLevel IN (DEBUG,INFO)]........... it is not giving desired results.
how can I search not IN as I was working on a solution building for not including multiple parameters.
What are the desired results?
When using subsearches, it helps to start with the subsearch by itself. Run the subsearch with the | format command added to see what the subsearch will return to the main search. That returned string must be proper SPL and make sense in your environment (fields must exist, etc.).
In the example shown, search logLevel IN (DEBUG,INFO) will return all events from the user's default indexes that contain a logLevel field with a value of "DEBUG" or "INFO".