Dashboards & Visualizations

How to hide a value from a mulstiselect filter?

KalebeRS
Explorer

Hello,
I have a value (imagine the value is the "something" that I wrote in the image)  in a multiselect  filter that I wanted to remove\hide, is there a way to do that?

KalebeRS_0-1687255349734.png

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

So you have a field called PR_Tags, with a value of "PR_Tags"?

index= host=  sourcetype=csv source=C:\\
| table PR_Tags
| where PR_Tags != "PR_Tags"

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Don't put it there in the first place!

How do you populate the drop down? If it is from a search, simply exclude the value from the results of the search.

0 Karma

KalebeRS
Explorer

 

index= host=  sourcetype=csv source=C:\\
| table PR_Tags
| eval PR_Tags=split(PR_Tags,",")
| mvexpand PR_Tags
| dedup PR_Tags

That's my search, it shouldn't be returning the term PR_Tags. 
Saw the file that I'm using for the search, the only time that mentions PR_Tags in the csv is in the header. Is there a way to remove the header?

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

So you have a field called PR_Tags, with a value of "PR_Tags"?

index= host=  sourcetype=csv source=C:\\
| table PR_Tags
| where PR_Tags != "PR_Tags"
0 Karma

KalebeRS
Explorer

It worked, thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...