In my search result I want to exclude some result that belongs to eventtype, Is it possible ?
my search is
sourcetype=log_line
I want to exclude all result from eventtype=procinfo
Hows about;
sourcetype=log_line NOT eventtype=procinfo
Theres no such thing as a stupid question! Its always quicker to ask if you aren't sure 🙂 Glad it helped
lol I am stupid 🙂
Thanks Drainy Splunk is really very powerful 🙂