<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Exclude Splunk's own audit trail log in search results? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Exclude-Splunk-s-own-audit-trail-log-in-search-results/m-p/636986#M221189</link>
    <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;I am new to Splunk. If criteria is met, I notice my search results include my previous searches stored in Splunk's own audit trail. They have:&lt;/P&gt;&lt;P&gt;host = [one of the Splunk nodes]&lt;/P&gt;&lt;P&gt;source = audittrail&lt;/P&gt;&lt;P&gt;sourcetype = audittrail&lt;/P&gt;&lt;P&gt;Is there a way to exclude it? It generates a lot of noise when I am refining my searches.. Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 31 Mar 2023 23:59:43 GMT</pubDate>
    <dc:creator>az365</dc:creator>
    <dc:date>2023-03-31T23:59:43Z</dc:date>
    <item>
      <title>Exclude Splunk's own audit trail log in search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Exclude-Splunk-s-own-audit-trail-log-in-search-results/m-p/636986#M221189</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;I am new to Splunk. If criteria is met, I notice my search results include my previous searches stored in Splunk's own audit trail. They have:&lt;/P&gt;&lt;P&gt;host = [one of the Splunk nodes]&lt;/P&gt;&lt;P&gt;source = audittrail&lt;/P&gt;&lt;P&gt;sourcetype = audittrail&lt;/P&gt;&lt;P&gt;Is there a way to exclude it? It generates a lot of noise when I am refining my searches.. Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Mar 2023 23:59:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Exclude-Splunk-s-own-audit-trail-log-in-search-results/m-p/636986#M221189</guid>
      <dc:creator>az365</dc:creator>
      <dc:date>2023-03-31T23:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Splunk's own audit trail log in search results?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Exclude-Splunk-s-own-audit-trail-log-in-search-results/m-p/636987#M221190</link>
      <description>&lt;P&gt;That will happen if you specify &lt;FONT face="courier new,courier"&gt;index=_audit&lt;/FONT&gt; in your query.&amp;nbsp; Don't do that if you don't want to see that data.&lt;/P&gt;&lt;P&gt;It also will happen if your default indexes list includes &lt;FONT face="courier new,courier"&gt;_*&lt;/FONT&gt; or &lt;FONT face="courier new,courier"&gt;_audit&lt;/FONT&gt; and you don't specify index name(s) in your query.&amp;nbsp; Don't do that.&amp;nbsp; Always include at least one index name in your queries (with few exceptions).&lt;/P&gt;&lt;P&gt;Or specifically exclude that source(type) in your query.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;blah blah source!=audittrail blah blah&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Apr 2023 00:08:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Exclude-Splunk-s-own-audit-trail-log-in-search-results/m-p/636987#M221190</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-04-01T00:08:39Z</dc:date>
    </item>
  </channel>
</rss>

