for example i have the string "update event from remote cache". i need to use NOT condition for this to capture ab events other than that.
You might want to look at rex Non-capturing which may do what you want with some rex trickery, but with out some samples its tough to tell. http://www.regular-expressions.info/refcapture.html
Does this not work (you MUST use ALL-CAPS for NOT
)?
NOT "event from remote cache"
Maybe this answer on Stack Overflow is of interest to you.
But maybe you could just eval a field which flags events with your given string and filter based on that eval'd field, such as
your_search | eval check=if(match(field, "update\sevent\sfrom\sremote\scache","nope","ok") | where check="ok"
PS: this assumes that your string in question is in a field named "field".