example : (warn OR error) NOT fail*
Retrieves all events containing either
“warn” or “error”, but not those that
have “fail”, “fails”, “failed”, failure”,
etc.
example 2 : sourcetype=syslog [search login error | return user]
here, search command, like all commands, can be used as a subsearch—a
search whose results are used as an argument to another search command.
Subsearches are enclosed in square brackets. For example, to find
all syslog events from the user that had the last login error, use the following
command: sourcetype=syslog [search login error | return user]
hope it gives some help to your query
... View more