Splunk Search

search query help

shri_27
Path Finder

Hi all,
I have 2 files, where suplierID,contractID are the common fields, Now I want to exclude the values of these fieds from 1st file if the value pair is present in 2nd file.how to achieve this??
plese help me for this.

Thanks in advance

Tags (1)
0 Karma

kristian_kolb
Ultra Champion

source=file1 NOT [search source=file2 | fields + suplierID contractID]

The subsearch gets executed first and returns the key/value pairs for the the two fields in question and then the outer search gets executed like so;

source=file1 NOT (( suplierID=X AND contractID=Y ) OR ( suplierID=X AND contractID=Z ) OR ... )

/K

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...