Splunk® Enterprise

Search Manual

Download manual as PDF

Download topic as PDF

Difference between NOT and !=

When you want to exclude results from your search you can use the NOT operator or the != field expression. However there is a significant difference in the results that are returned from these two methods.

Suppose you have the following fields:

  • fieldA
  • fieldB
  • fieldC


Each of these fields has 3 different values. For example fieldA has value1, value2, and value3.

Searching with !=

If you search for fieldB!=value3, the search returns only those values for fieldB that are not value3:

  • fieldB=value1, fieldB=value2


If fieldB does not exist, nothing is returned.

Searching with NOT

If you search for NOT fieldB=value3, the search returns everything except fieldB=value3:

  • fieldA=value1, fieldA=value2, fieldA=value3
  • fieldB=value1, fieldB=value2
  • fieldC=value1, fieldC=value2, fieldC=value3


If fieldB does not exist, NOT fieldB=value3 returns:

  • fieldA=value1, fieldA=value2, fieldA=value3
  • fieldC=value1, fieldC=value2, fieldC=value3
PREVIOUS
Field expressions
  NEXT
Use CASE() and TERM() to match phrases

This documentation applies to the following versions of Splunk® Enterprise: 6.2.0, 6.2.1, 6.2.2, 6.2.3, 6.2.4, 6.2.5, 6.2.6, 6.2.7, 6.2.8, 6.2.9, 6.2.10, 6.2.11, 6.2.12, 6.2.13, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.4.6, 6.4.7, 6.4.8, 6.4.9, 6.5.0, 6.5.1, 6.5.1612 (Splunk Cloud only), 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.6.4, 7.0.0


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters