Answer by warren for Splunk query not endswith

You can do this with a search and where clause:

| inputlookup myfile.csv 
| search support_group="mygroup-Linux" u_sec_dom="Normal Secure"
| where !match(fqdn,"udc.net$") AND !match(fqdn,"htc.com$") 

Or just a single search clause:

| inputlookup myfile.csv
| search support_group="mygroup-Linux" u_sec_dom="Normal Secure" NOT (fqdn IN("*udc.net","*htc.com")

You can also rewrite the IN() thusly:

(fqdn="*udc.net" OR fqdn="*htc.com")

from User warren – Stack Overflow https://stackoverflow.com/questions/66643257/splunk-query-not-endswith/66655995#66655995
via IFTTT