i am trying the exclude the events in the sub search query using Search NOT. It is not returning the expected result. in this i am trying to exclude "system=APICleanUp callbacknumber=* Message="API Success" sourcetype=application_prod" events. Both the logs are are coming from 2 different system..callback is the common field between two search queries. Query: environment=PROD system=API1 Message="API l logs"|dedup callbacknumber | search NOT [search system=APICleanUp callbacknumber=* Message="API Success" sourcetype=application_prod ]| table callbacknumber Any help will be highly appreciated
... View more