- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

jangid
Builder
07-05-2012
06:31 AM
In my search result I want to exclude some result that belongs to eventtype, Is it possible ?
my search is
sourcetype=log_line
I want to exclude all result from eventtype=procinfo
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Drainy
Champion
07-05-2012
06:33 AM
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Drainy
Champion
07-05-2012
06:33 AM
Hows about;
sourcetype=log_line NOT eventtype=procinfo
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Drainy
Champion
07-05-2012
07:15 AM
Theres no such thing as a stupid question! Its always quicker to ask if you aren't sure 🙂 Glad it helped
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

jangid
Builder
07-05-2012
07:14 AM
lol I am stupid 🙂
Thanks Drainy Splunk is really very powerful 🙂
