All Apps and Add-ons

Cisco Networks App for Splunk Enterprise: How to exclude certain field from main dashboard?

Coldfirex
New Member

Howdy,
Is there a way to exclude a certain error from being used in the main dashboard? For instance in the "Syslog severity distribution" without not having IOS log it?
Thanks!

0 Karma

dbcase
Motivator

Have you tried something like this

your search here|where yourerrorcodefield!=yourerrorcodevaluethatyouwanttoexclude|rest of your search

-or-

your index here your sourcetype here yourerrorcodefield!=yourerrorcodevaluethatyouwanttoexclude|rest of your search
0 Karma

Coldfirex
New Member

This wouldnt be manual searches, but the actual dashboard. Is the dashboard editable?

0 Karma

dbcase
Motivator

It depends on how the dashboard is setup but it is possible. Do you have an edit button in the top right hand corner of the dashboard? If so, click on it then click on the magnifying glass in the top right hand corner of the panel you are interested in. Then click edit search then modify the search string and click apply.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...