NOT host=10.10.10.10 NOT process=apache2 NOT process=mysql
Please also be aware that NOT process=apache2
is NOT the same as process!=apache2
. The former keeps events where isnull(process)
is TRUE, whereas the latter does not (drops events where isnull(process)
is TRUE. This may matter to you.
You're a God!
Just to add something; NOT
search should be avoided, especially in regards of search performance and scalability. See the docs about this http://docs.splunk.com/Documentation/Splunk/6.2.4/Search/Writebettersearches#Tips_for_tuning_your_se...
Thanks for the tips. But no worries I just used it in order to extract a specific details from a data that I uploaded