brunotm / elasticsplunk

A Search command to explore Elasticsearch data within Splunk.
MIT License
40 stars 25 forks source link

query against on Mulitple index #25

Open yuvarajanlga opened 5 years ago

yuvarajanlga commented 5 years ago

Hi,

how to execute the similar below command on multiple index.

For example in splunk.

index= OR index=_ NOT index=main NOT index=history NOT sourcetype=stash

can we do the same thing here as well ? i tried but its not working. if you could let me know how to do , then it will be very helpful. thanks.