<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ignoring extracted value in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/ignoring-extracted-value/m-p/70128#M17569</link>
    <description>&lt;P&gt;I want to ignore certain search results from by search. Now one way is below where I can filter the extracted value, which I am using currently. This is not the great solution though, as I already have around 6-7 filter in search command.  Now adding more will create a big problem for me. as every time i need to add using new pipe.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;some search string | eval puserid = mvfilter(puserid != 211930670 ) | eval puserid = mvfilter(puserid != 212327191 ) | eval puserid = mvfilter(puserid != 211896322 ) | eval puserid = mvfilter(puserid != 212327208 | stats 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;somehow this is working fine, till I come to another use case where I need to ignore these values on daily basis. Now I have created n searches and on top of that a Dashboard. going modifying one by one is time consuming. Also, that is not viable solution. I am looking for a solution, where I can pass information which can be ignored from extracted results and I need not to modify my searches. &lt;/P&gt;</description>
    <pubDate>Sun, 04 Sep 2011 17:45:24 GMT</pubDate>
    <dc:creator>sumitnagal</dc:creator>
    <dc:date>2011-09-04T17:45:24Z</dc:date>
    <item>
      <title>ignoring extracted value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ignoring-extracted-value/m-p/70128#M17569</link>
      <description>&lt;P&gt;I want to ignore certain search results from by search. Now one way is below where I can filter the extracted value, which I am using currently. This is not the great solution though, as I already have around 6-7 filter in search command.  Now adding more will create a big problem for me. as every time i need to add using new pipe.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;some search string | eval puserid = mvfilter(puserid != 211930670 ) | eval puserid = mvfilter(puserid != 212327191 ) | eval puserid = mvfilter(puserid != 211896322 ) | eval puserid = mvfilter(puserid != 212327208 | stats 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;somehow this is working fine, till I come to another use case where I need to ignore these values on daily basis. Now I have created n searches and on top of that a Dashboard. going modifying one by one is time consuming. Also, that is not viable solution. I am looking for a solution, where I can pass information which can be ignored from extracted results and I need not to modify my searches. &lt;/P&gt;</description>
      <pubDate>Sun, 04 Sep 2011 17:45:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ignoring-extracted-value/m-p/70128#M17569</guid>
      <dc:creator>sumitnagal</dc:creator>
      <dc:date>2011-09-04T17:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: ignoring extracted value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ignoring-extracted-value/m-p/70129#M17570</link>
      <description>&lt;P&gt;I'm not sure I understand why your are using eval as such, as it is suboptimal.  As a rule of thumb, filtering should be performed before the first pipe symbol.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;some search string NOT puserid=211930670 NOT puserid=212327191 ... | stats ...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;A more efficient solution would be to use a lookup or eventtypes and tags to manage the list of puserid that you want to exclude.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Sep 2011 18:58:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ignoring-extracted-value/m-p/70129#M17570</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2011-09-04T18:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: ignoring extracted value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ignoring-extracted-value/m-p/70130#M17571</link>
      <description>&lt;P&gt;the only problem is I am getting puserid from a search string, hence I am thinking of using like this way&lt;/P&gt;

&lt;P&gt;some search string |rex field=_raw " (?&lt;URI&gt;[^ ]&lt;EM&gt;) (?&lt;PRIMARY&gt;[A-Za-z]&lt;/PRIMARY&gt;&lt;/EM&gt;) (?&lt;PUSERID&gt;[^ ]&lt;EM&gt;) (?&lt;PURI&gt;[^ ]&lt;/PURI&gt;&lt;/EM&gt;) " | eval puserid = mvfilter(puserid != 211930670 ) | eval puserid = mvfilter(puserid != 212327191 ) | eval puserid = mvfilter(puserid != 211896322 ) | eval puserid = mvfilter(puserid != 212327208 | stats&lt;/PUSERID&gt;&lt;/URI&gt;&lt;/P&gt;

&lt;P&gt;let me know, if there are better ways to do so.&lt;/P&gt;

&lt;P&gt;Also, in your suggestion every time I need to add puserid, which I want to ignore in my use case.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2011 13:36:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ignoring-extracted-value/m-p/70130#M17571</guid>
      <dc:creator>sumitnagal</dc:creator>
      <dc:date>2011-09-06T13:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: ignoring extracted value</title>
      <link>https://community.splunk.com/t5/Splunk-Search/ignoring-extracted-value/m-p/70131#M17572</link>
      <description>&lt;P&gt;I have used lookup which has solved the problem, but now everytime I need to update lookup.csv file. Currently I am deleting existing lookup file and uploading new lookup file with values. &lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2011 14:26:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/ignoring-extracted-value/m-p/70131#M17572</guid>
      <dc:creator>sumitnagal</dc:creator>
      <dc:date>2011-09-07T14:26:27Z</dc:date>
    </item>
  </channel>
</rss>

