Hello,
You can put specific strings with quotes like
sourcetype=x "string"|..../sourcetype=x NOT "string"|....
this will give you the events containing/not with the string.
Or you can go for match/searchmatch in eval
http://docs.splunk.com/Documentation/Splunk/5.0.4/SearchReference/CommonEvalFunctions
Thanks
Hello,
You can put specific strings with quotes like
sourcetype=x "string"|..../sourcetype=x NOT "string"|....
this will give you the events containing/not with the string.
Or you can go for match/searchmatch in eval
http://docs.splunk.com/Documentation/Splunk/5.0.4/SearchReference/CommonEvalFunctions
Thanks
or if it is only one string not a type of strings just put quotes around it in the search
rex commands see: http://docs.splunk.com/Documentation/Splunk/5.0.4/SearchReference/Rex