NOT sourcetype=top NOT sourcetype=ps NOT sourcetype=openPorts
Something along the lines of
NOT sourcetype in (top, ps, openPorts)
Thanks for the help!
Oh .. and one more question, there's a shortcut to insert "NOT sourcetype=blah" by holding down a key combination and mouse clicking on the "blah" in the current search results. What is the key combination on both windows and mac? Thanks.
well, your example is not an OR search, it is an AND search. The AND directive is implied between terms, so you do not need to write it - this means
`foo AND bar`
is the same like this
Back to your question: to search for multiple OR statements you can do something like this:
`NOT ( sourcetype="top" OR sourcetype="ps" OR sourcetype="openPorts" )`
Please see the docs on writing better searches, where you can see that one should avoid NOT searches but instead search for event you want. NOT searches will have negative performance impact on long time searches.