I found a close answer to what I'm looking for here: https://community.splunk.com/t5/Splunk-Search/Why-cant-i-supply-a-field-as-value-for-mvfilter/m-p/450564/highlight/true#M127583 The example, excludes 1 example, add \"a\" for more, which works: | makeresults
| eval mymvfield ="a b c"
| makemv mymvfield
| eval excludes = mvfilter(NOT in(mymvfield,
[| makeresults
| eval search = "\"b\""
| return $search])) What I'm looking for, use return which seemingly translates to (b) OR (a) ... : | makeresults
| eval mymvfield ="a b c"
| makemv mymvfield
| eval excludes = mvfilter(NOT in(mymvfield,
[| search something
| return 3 $some_field])) I get weird parsing errors which I thought maybe could be solved by using "format" but I'm at a loss. I reckon you could probably solve this by doing a subsearch and filtering prior to making the multivalue field, I'm however curious if you can make this query work. Please let me know if anything is unclear.
... View more