I believe what you're looking to do should be implicitly solved by searching NOT field=value When searching with != you are also telling Splunk to only return results with a valid entry for that field. Take a look at the documentation for Difference between != and NOT for an in-depth breakdown of the differences. But @foxglove your question is a bit ambiguous, are you searching against two separate fields, looking for both null/nonexistent value and non-excluded values, or only null/nonexistent values that also don't match the searched value?
... View more