Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Joe_Kanaszka
Advisor
Jump to solution

Can't seem to add more than 3 filters in Smart Log

Hey all - 

 

I'm trying to dynamically add filters in Smart Log to filter some traffic.  I'll right click on an entry and the service I'm filtering and click "add to filter" & "OR NOT snmp", and so on...until I reach the 4th filter. 

It doesn't filter...

So in this example:

NOT service:https OR NOT service:domain-udp OR NOT service:igmp OR NOT service:snmp

 

So in the above filter, traffic with snmp as a service is still showing.

 

Any ideas?

0 Kudos
1 Solution

Accepted Solutions
JozkoMrkvicka
Authority
Authority

Try this syntax (including brackets):

NOT (service:https OR service:domain-udp OR service:igmp OR service:snmp)

Kind regards,
Jozko Mrkvicka

View solution in original post

(1)
8 Replies
the_rock
MVP Diamond
MVP Diamond

Hey brother,

Are you saying that filter does NOT work?

Andy

Best,
Andy
"Have a great day and if its not, change it"
garrod
Contributor

Hi,

Open TAC case or RFE, this command is not working in my R81.20 as well, Enhancement required for R&D Team

 

They able to work with

source:1.1.1.1 NOT destination:2.2.2.2 NOT destination: 3.3.3.3

or

source:1.1.1.1 OR destination:2.2.2.2 OR destination: 3.3.3.3

 

combing NOT and OR will not work

the_rock
MVP Diamond
MVP Diamond

That makes sense. I will confirm in my lab as well.

Andy

Best,
Andy
"Have a great day and if its not, change it"
JozkoMrkvicka
Authority
Authority

Try this syntax (including brackets):

NOT (service:https OR service:domain-udp OR service:igmp OR service:snmp)

Kind regards,
Jozko Mrkvicka
(1)
G_W_Albrecht
MVP Silver
MVP Silver

Right, same as my versions above - everything except service1, service 2. service3, service4

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
the_rock
MVP Diamond
MVP Diamond

Thats it!

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
Joe_Kanaszka
Advisor

This works -

Thank you Jozko!

G_W_Albrecht
MVP Silver
MVP Silver

Logically, OR does not make any sense here: NOT service1 is everything except service1, including service2. NOT service2 includes service1, but not service2.

So either use:

NOT service:https AND NOT service:domain-udp AND NOT service:tunnel_test AND NOT service:igmp

When you use queries with more than one criteria value, an AND is implied automatically, so there is no need to add it.

NOT service:https NOT service:domain-udp NOT service:tunnel_test NOT service:igmp

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events