Nevermind.. Known issue
2019-11-11 SPL-179357, SPL-179700 Negated subnet CIDR filter doesn't work in search.
limits.conf: [search] use_search_evaluator_v2=false
Examples searches that don't filter out values: index=_internal (NOT clientip= | stats count BY clientip
index=_internal (clientip!= | stats count BY clientip
index=_internal | stats count BY clientip | search (clientip!= | stats sum(count) BY clientip | noop search_optimization=false
Filtering with | where is OK: index=_internal | where NOT cidrmatch("", clientip) | stats count BY clientip
... View more