I have logs that say both contact and non contact. I would like to distinguish them in a search with the complete "non contact" but eliminate all that just say "contact".
@here2infinity
You can use like this directly
<your query> "non contacts" to show the logs only it has the term
<your query> NOT "non contacts" to show the logs only the contacts term has.
I have tested in my splunk and it is working.