regex - How to ignore a specific sub-string from Splunk query -



regex - How to ignore a specific sub-string from Splunk query -

need help generate appropriate spunk query. searching not come solution.

currently, want ignore error alerts generated logs ev31=error; term. if utilize not ev31=error; in search query, removes results valid error terms. current query fail in case log contains both error , ev31=error; terms resulting in wrong results.

can suggest illustration query, can ignore ev31=error; term altogether maintain logs error term.

try including string want ignore in quotes, search might index=myindex not "ev31=error"

regex splunk

Comments

Popular posts from this blog

php - Android app custom user registration and login with cookie using facebook sdk -

django - Access session in user model .save() -

php - .htaccess Multiple Rewrite Rules / Prioritizing -