I tried for an hour but couldn't find the answer.
I need to search my syslogs from a specific host for entries that do not contain the word Interface my current search line is:
sourcetype="cisco_syslog" host="10.10.10.10"
I tried
sourcetype="cisco_syslog" host="10.10.10.10" | regex _raw(=|!=) [\ )?Interface(\]
but it doesn't work.
I'm sure I'm close but I am terrible at regular expressions.
... View more