Hi dxw350,
no it would not override the removal of the ip address.
You could also first write
sourcetype=linux host_ip=* host_ip!=192.168.1.4 |table host_ip
it wouldn't chance anything.
The search conditions are by joined by default logical operator of 'AND' , so your wildcard filter will still be applicable.
If you're including host_ip=*
only to get events which non-null value of host_ip, then it's not required as host_ip!=192.168.1.4
will eliminate any event which has host_ip=null. (if you use NOT host_ip=192.168.1.4
then it'll return events with host_ip=null, if any.