<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Only Filtering for Interesting Event Logs in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Only-Filtering-for-Interesting-Event-Logs/m-p/30716#M5385</link>
    <description>&lt;P&gt;Sounds like an excellent solution.  Do you know if there is a character limit in a Macro?  If so, I imagine at some point I would need to string them together in series.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Nov 2012 21:00:52 GMT</pubDate>
    <dc:creator>wbordeau</dc:creator>
    <dc:date>2012-11-12T21:00:52Z</dc:date>
    <item>
      <title>Only Filtering for Interesting Event Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Only-Filtering-for-Interesting-Event-Logs/m-p/30714#M5383</link>
      <description>&lt;P&gt;Is there a way to express a series of exclude filters as variable in a search?&lt;/P&gt;

&lt;P&gt;What I want to do is create a search and eventually an alert that will trigger on all Event Log Warnings and Errors until I exclude them one by one in the search.  I realize the search string would grow impossibly long so I want to know if there is a way to condense the excluded filters and represent them with a single constant or variable that would be updated and vetted on an ongoing basis.&lt;/P&gt;

&lt;P&gt;Having this type of search would only yield events that I don't yet know about that could be important for me to investigate while at the same time filter out events I already know about and can safely ignore.&lt;/P&gt;

&lt;P&gt;I'm open to other alternatives but this is basically the impetus of what I want to accomplish.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2012 15:55:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Only-Filtering-for-Interesting-Event-Logs/m-p/30714#M5383</guid>
      <dc:creator>wbordeau</dc:creator>
      <dc:date>2012-11-12T15:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Only Filtering for Interesting Event Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Only-Filtering-for-Interesting-Event-Logs/m-p/30715#M5384</link>
      <description>&lt;P&gt;You could use a macro and update it over time as you add various known filters.  That would simplify your search string.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Search/Usesearchmacros#Create_search_macros_in_Splunk_Web"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Search/Usesearchmacros#Create_search_macros_in_Splunk_Web&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2012 16:04:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Only-Filtering-for-Interesting-Event-Logs/m-p/30715#M5384</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-11-12T16:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: Only Filtering for Interesting Event Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Only-Filtering-for-Interesting-Event-Logs/m-p/30716#M5385</link>
      <description>&lt;P&gt;Sounds like an excellent solution.  Do you know if there is a character limit in a Macro?  If so, I imagine at some point I would need to string them together in series.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2012 21:00:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Only-Filtering-for-Interesting-Event-Logs/m-p/30716#M5385</guid>
      <dc:creator>wbordeau</dc:creator>
      <dc:date>2012-11-12T21:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: Only Filtering for Interesting Event Logs</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Only-Filtering-for-Interesting-Event-Logs/m-p/30717#M5386</link>
      <description>&lt;P&gt;It looks like it's not about the number of characters.  Take a look. &lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/8399/what-is-the-max-character-limit-for-a-macro"&gt;http://splunk-base.splunk.com/answers/8399/what-is-the-max-character-limit-for-a-macro&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Nov 2012 21:04:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Only-Filtering-for-Interesting-Event-Logs/m-p/30717#M5386</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-11-12T21:04:19Z</dc:date>
    </item>
  </channel>
</rss>

