Splunk Search

exclude 'sendmail' in search options

subhap
Engager

I am using the following in my search options: index="my_site_hosts" "hostABC" "failed"

The results displays sendmail. I want to filter out sendmail and see all other failures.

How do I exclude sendmail in the search results so I get to view other forms of failures?

I did try this: index="my_site_hosts" "hostABC" "failed" !"sendmail" the negation sign did not work?

thank you

Tags (1)

Genti
Splunk Employee
Splunk Employee

subhap try:
index="my_site_hosts" "hostABC" "failed" NOT "sendmail"

Cheers,
.gz

gkanapathy
Splunk Employee
Splunk Employee
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...