All Apps and Add-ons

Cisco Networks App for Splunk Enterprise: How to exclude certain field from main dashboard?

Coldfirex
New Member

Howdy,
Is there a way to exclude a certain error from being used in the main dashboard? For instance in the "Syslog severity distribution" without not having IOS log it?
Thanks!

0 Karma

dbcase
Motivator

Have you tried something like this

your search here|where yourerrorcodefield!=yourerrorcodevaluethatyouwanttoexclude|rest of your search

-or-

your index here your sourcetype here yourerrorcodefield!=yourerrorcodevaluethatyouwanttoexclude|rest of your search
0 Karma

Coldfirex
New Member

This wouldnt be manual searches, but the actual dashboard. Is the dashboard editable?

0 Karma

dbcase
Motivator

It depends on how the dashboard is setup but it is possible. Do you have an edit button in the top right hand corner of the dashboard? If so, click on it then click on the magnifying glass in the top right hand corner of the panel you are interested in. Then click edit search then modify the search string and click apply.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...