Dashboards & Visualizations

How to hide a value from a mulstiselect filter?

KalebeRS
Explorer

Hello,
I have a value (imagine the value is the "something" that I wrote in the image)  in a multiselect  filter that I wanted to remove\hide, is there a way to do that?

KalebeRS_0-1687255349734.png

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

So you have a field called PR_Tags, with a value of "PR_Tags"?

index= host=  sourcetype=csv source=C:\\
| table PR_Tags
| where PR_Tags != "PR_Tags"

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Don't put it there in the first place!

How do you populate the drop down? If it is from a search, simply exclude the value from the results of the search.

0 Karma

KalebeRS
Explorer

 

index= host=  sourcetype=csv source=C:\\
| table PR_Tags
| eval PR_Tags=split(PR_Tags,",")
| mvexpand PR_Tags
| dedup PR_Tags

That's my search, it shouldn't be returning the term PR_Tags. 
Saw the file that I'm using for the search, the only time that mentions PR_Tags in the csv is in the header. Is there a way to remove the header?

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

So you have a field called PR_Tags, with a value of "PR_Tags"?

index= host=  sourcetype=csv source=C:\\
| table PR_Tags
| where PR_Tags != "PR_Tags"
0 Karma

KalebeRS
Explorer

It worked, thanks!

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...