I would like to exclude log messages for which I only partially know what string that I want to exclude will contain. Is this possible within the keyword portion of the search?
For example: My log file contains the following 3 entries:
Jan 15 21:47:47 47-e100 workerthread: be60: b6794ab0 00000000 bb4ab480 2ac99000 8000000 b6975b00 bb4ab480 2ac99000
Jan 17 21:47:48 47-d312 workerthread:
Jan 17 21:47:49 47-04a1 workerthread: Internal Error
I would like to exclude them from my search results in the keyword search if possible. For example to exclude the last line I would use the following in my keyword search for example:
(_sourceCategory=log/logmessages AND "workerthread") AND !"Internal Error"
How can I exclude anything in the logs that contains "workerthread: b"? (Log line 1) because the following doesn't work:
(_sourceCategory=log/logmessages AND "workerthread") AND !"workerthread: b*"
How can I exclude anything that is blank after a workerthread:? (Log line 2)
Please sign in to leave a comment.