<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Source code to remove host from Dashboard in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Where-to-enter-source-code-to-remove-host-from-Dashboard/m-p/613923#M50350</link>
    <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229311"&gt;@andrew_nelson&lt;/a&gt;&amp;nbsp;!&amp;nbsp; Is there a way that I could just add an "text" input in the dashboard that says src_ip!=10.0.0.1?&amp;nbsp; I think this is a more scalable way since I have other apps that I would want to exclude the host from as well.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Sep 2022 12:38:40 GMT</pubDate>
    <dc:creator>Ted1621</dc:creator>
    <dc:date>2022-09-21T12:38:40Z</dc:date>
    <item>
      <title>Where to enter source code to remove host from Dashboard?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Where-to-enter-source-code-to-remove-host-from-Dashboard/m-p/613904#M50348</link>
      <description>&lt;P&gt;I have one host that I want to remove from all my premade dashboards in the Splunk App for AWS Security Dashboards.&amp;nbsp; Can someone tell me where I would enter this in the source code for the Dashboard so that it always excludes this host?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 14:16:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Where-to-enter-source-code-to-remove-host-from-Dashboard/m-p/613904#M50348</guid>
      <dc:creator>Ted1621</dc:creator>
      <dc:date>2022-09-21T14:16:56Z</dc:date>
    </item>
    <item>
      <title>Re: Source code to remove host from Dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Where-to-enter-source-code-to-remove-host-from-Dashboard/m-p/613905#M50349</link>
      <description>&lt;P&gt;Take a look the the macros that come with the app. Settings &amp;gt; Advanced Search &amp;gt; Search Macros&lt;BR /&gt;You'll find some index macros like `aws-security-cloudtrail-index`, `aws-security-config-index`&amp;nbsp;etc.&amp;nbsp; that are used to specify the data used throughout the app.&lt;/P&gt;&lt;P&gt;You can edit these to to add host!="hostabc" and the host should be removed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 11:25:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Where-to-enter-source-code-to-remove-host-from-Dashboard/m-p/613905#M50349</guid>
      <dc:creator>andrew_nelson</dc:creator>
      <dc:date>2022-09-21T11:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: Source code to remove host from Dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Where-to-enter-source-code-to-remove-host-from-Dashboard/m-p/613923#M50350</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229311"&gt;@andrew_nelson&lt;/a&gt;&amp;nbsp;!&amp;nbsp; Is there a way that I could just add an "text" input in the dashboard that says src_ip!=10.0.0.1?&amp;nbsp; I think this is a more scalable way since I have other apps that I would want to exclude the host from as well.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 12:38:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Where-to-enter-source-code-to-remove-host-from-Dashboard/m-p/613923#M50350</guid>
      <dc:creator>Ted1621</dc:creator>
      <dc:date>2022-09-21T12:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: Source code to remove host from Dashboard</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Where-to-enter-source-code-to-remove-host-from-Dashboard/m-p/613929#M50352</link>
      <description>&lt;P&gt;Yeah, if you have Edit permissions on the dashboards, you can add&amp;nbsp;&lt;SPAN&gt;src_ip!=10.0.0.1 into the searches.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;It could be a lot of work depending on how the dashboard panels are configured. If the dashboard uses a base search, it will be quick enough to do that dashboard. If the dashboard doesn't have a base search, you'll have to edit every single panel.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2022 13:05:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Where-to-enter-source-code-to-remove-host-from-Dashboard/m-p/613929#M50352</guid>
      <dc:creator>andrew_nelson</dc:creator>
      <dc:date>2022-09-21T13:05:41Z</dc:date>
    </item>
  </channel>
</rss>

