Stll not very clear to me. index=doc1 sourcetype=at-doc1 NOT [| inputlookup yourExceptionLookup.csv | table exception ] Let say i have the index doc1, and sourcetype=at-doc1. If i perform this search will extract all the events, even what i have in the file(if the log is different but include the exception name). I expect to get some exception that are not in the .csv. I'm doing something wrong? Somehow i want to get the type of exceptions that never happened before and fully exclude the exceptions i know from file. Is that possible? As you can see my environment(logs) are different everytime i dont know if this is the cause but even if they are different i want to exclude entire log if this is contain something from the .csv
... View more