<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exclude Hosts In A Saved Search in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Exclude-Hosts-In-A-Saved-Search/m-p/23043#M4057</link>
    <description>&lt;P&gt;to expand on your question, do you wish to only exclude these drives if it reaches a certain threshold? Or do you mean you simply want to exclude these drives from the start?&lt;/P&gt;

&lt;P&gt;If it is the latter, you could just add something like "&lt;CODE&gt;NOT host=&amp;lt;drive name&amp;gt;&lt;/CODE&gt;" (if you are using the drive as the host)&lt;/P&gt;</description>
    <pubDate>Mon, 28 Nov 2011 13:31:09 GMT</pubDate>
    <dc:creator>MHibbin</dc:creator>
    <dc:date>2011-11-28T13:31:09Z</dc:date>
    <item>
      <title>Exclude Hosts In A Saved Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Exclude-Hosts-In-A-Saved-Search/m-p/23042#M4056</link>
      <description>&lt;P&gt;I have a saved search that is looking at the % disk space free on each drive over a number of window server. There are three servers that are showing over a certain threshold.  Is there anyway to add in an exlude syntax in the saved search to not report on these three servers.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2011 13:27:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Exclude-Hosts-In-A-Saved-Search/m-p/23042#M4056</guid>
      <dc:creator>itsomana</dc:creator>
      <dc:date>2011-11-28T13:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Hosts In A Saved Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Exclude-Hosts-In-A-Saved-Search/m-p/23043#M4057</link>
      <description>&lt;P&gt;to expand on your question, do you wish to only exclude these drives if it reaches a certain threshold? Or do you mean you simply want to exclude these drives from the start?&lt;/P&gt;

&lt;P&gt;If it is the latter, you could just add something like "&lt;CODE&gt;NOT host=&amp;lt;drive name&amp;gt;&lt;/CODE&gt;" (if you are using the drive as the host)&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2011 13:31:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Exclude-Hosts-In-A-Saved-Search/m-p/23043#M4057</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2011-11-28T13:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Hosts In A Saved Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Exclude-Hosts-In-A-Saved-Search/m-p/23044#M4058</link>
      <description>&lt;P&gt;Hi, many thanks for your reply.  The NOT host is working but I would like to exclude the host name along with drive letter (instance) for each server&lt;/P&gt;

&lt;P&gt;Below is what I see in Splunk when I run my % disk space free query: &lt;/P&gt;

&lt;P&gt;11/28/2011 14:54:20.073&lt;BR /&gt;
collection="Free Disk Space E"&lt;BR /&gt;
object=LogicalDisk&lt;BR /&gt;
counter="% Free Space"&lt;BR /&gt;
instance=E:&lt;BR /&gt;
Value=45.903129070366219&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2011 15:06:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Exclude-Hosts-In-A-Saved-Search/m-p/23044#M4058</guid>
      <dc:creator>itsomana</dc:creator>
      <dc:date>2011-11-28T15:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Hosts In A Saved Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Exclude-Hosts-In-A-Saved-Search/m-p/23045#M4059</link>
      <description>&lt;P&gt;Have you done a field extraction for the "instance" field?&lt;/P&gt;

&lt;P&gt;Do you mean... you would like to exclude events similar to this (i.e. those from drive E)? Or you want to exclude the drive instance just from the results?&lt;/P&gt;

&lt;P&gt;Can you include your saved search in this thread please?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2011 15:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Exclude-Hosts-In-A-Saved-Search/m-p/23045#M4059</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2011-11-28T15:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude Hosts In A Saved Search</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Exclude-Hosts-In-A-Saved-Search/m-p/23046#M4060</link>
      <description>&lt;P&gt;If you have done a field extraction on the instance, and you just want to exclude all events from that drive, you could also include a...&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;NOT instance=E: | &lt;REST of="" search=""&gt; (for example). &lt;/REST&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If not you could do something like... &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;| rex field=_raw "instance=\s*(?&lt;INSTANCE&gt;\w*):"&lt;/INSTANCE&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;However this should be done by default (except it will include the ":"), and then add pipe to a search...&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;| rex field=_raw "instance=\s*(?&lt;INSTANCE&gt;\w*):" | search NOT INSTANCE=E | &lt;REST of="" search=""&gt;&lt;/REST&gt;&lt;/INSTANCE&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;But this could be a little inefficient, preferably you would want to extract the field using IFX.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:09:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Exclude-Hosts-In-A-Saved-Search/m-p/23046#M4060</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2020-09-28T10:09:36Z</dc:date>
    </item>
  </channel>
</rss>

