All Apps and Add-ons

Cisco Networks App for Splunk Enterprise: How to exclude certain field from main dashboard?

Coldfirex
New Member

Howdy,
Is there a way to exclude a certain error from being used in the main dashboard? For instance in the "Syslog severity distribution" without not having IOS log it?
Thanks!

0 Karma

dbcase
Motivator

Have you tried something like this

your search here|where yourerrorcodefield!=yourerrorcodevaluethatyouwanttoexclude|rest of your search

-or-

your index here your sourcetype here yourerrorcodefield!=yourerrorcodevaluethatyouwanttoexclude|rest of your search
0 Karma

Coldfirex
New Member

This wouldnt be manual searches, but the actual dashboard. Is the dashboard editable?

0 Karma

dbcase
Motivator

It depends on how the dashboard is setup but it is possible. Do you have an edit button in the top right hand corner of the dashboard? If so, click on it then click on the magnifying glass in the top right hand corner of the panel you are interested in. Then click edit search then modify the search string and click apply.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...