Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

filtering search to exclude all instances of field 1 for when certain results in field 2

$
0
0
I have a search that brakes down some router alarms . my fields are Host_IP & Alarm What I'm trying to do is filter for hosts that only take a specific alarm and do not have certain alarms. these are state changes . these alarms are SessionUp SessionDown SessionProtChange Im looking to isolate Hosts that only exhibit SessionUp alarm without having the usual SessionDown and SessionProtChange Thanks.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>