Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I filter results based on approximately 115 partial values of a field?

$
0
0
I have a list large list of products. I need to search the list but filtering out some results based on the partial values of the **ProdDesc** field. Examples of ProdDesc would be something like : MD5864,WINDOWS,PROC1 or MA9874,ANDROID,PROC3, etc. I can use `ProdDesc != \*5864\* and ProdDesc != \*ANDROID\*...`. The problem is that the list of partial results has 112 items. When I add `ProdDesc != \*[partial value]\*` more than 26 times, the query returns no result at all. There seems to be a limitation of how many times I can use `!=\*[partial value]\*`. I'm using Splunk Enterprise version 6.5.3 and I'm an end user, not an Admin. I wold appreciate any help provided. Thank you.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>