Splunk Search

search query

DTERM
Contributor

What is wrong with the following?

index="app" | top productName NOT productName = "Not Specified"

I want to extract a list of product names but I don't want to include "Not Specified" as part of the set.

TIA

Tags (1)
0 Karma
1 Solution

sfleming
Splunk Employee
Splunk Employee

Try excluding "not specified" in the original search string, before calling the top command. Also, use !=

index="app" productName!="Not Specified" | top productName

View solution in original post

0 Karma

sfleming
Splunk Employee
Splunk Employee

Try excluding "not specified" in the original search string, before calling the top command. Also, use !=

index="app" productName!="Not Specified" | top productName
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...