Dashboards & Visualizations

How to hide a value from a mulstiselect filter?

KalebeRS
Explorer

Hello,
I have a value (imagine the value is the "something" that I wrote in the image)  in a multiselect  filter that I wanted to remove\hide, is there a way to do that?

KalebeRS_0-1687255349734.png

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

So you have a field called PR_Tags, with a value of "PR_Tags"?

index= host=  sourcetype=csv source=C:\\
| table PR_Tags
| where PR_Tags != "PR_Tags"

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Don't put it there in the first place!

How do you populate the drop down? If it is from a search, simply exclude the value from the results of the search.

0 Karma

KalebeRS
Explorer

 

index= host=  sourcetype=csv source=C:\\
| table PR_Tags
| eval PR_Tags=split(PR_Tags,",")
| mvexpand PR_Tags
| dedup PR_Tags

That's my search, it shouldn't be returning the term PR_Tags. 
Saw the file that I'm using for the search, the only time that mentions PR_Tags in the csv is in the header. Is there a way to remove the header?

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

So you have a field called PR_Tags, with a value of "PR_Tags"?

index= host=  sourcetype=csv source=C:\\
| table PR_Tags
| where PR_Tags != "PR_Tags"
0 Karma

KalebeRS
Explorer

It worked, thanks!

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...