Dashboards & Visualizations

How to hide a value from a mulstiselect filter?

KalebeRS
Explorer

Hello,
I have a value (imagine the value is the "something" that I wrote in the image)  in a multiselect  filter that I wanted to remove\hide, is there a way to do that?

KalebeRS_0-1687255349734.png

 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

So you have a field called PR_Tags, with a value of "PR_Tags"?

index= host=  sourcetype=csv source=C:\\
| table PR_Tags
| where PR_Tags != "PR_Tags"

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Don't put it there in the first place!

How do you populate the drop down? If it is from a search, simply exclude the value from the results of the search.

0 Karma

KalebeRS
Explorer

 

index= host=  sourcetype=csv source=C:\\
| table PR_Tags
| eval PR_Tags=split(PR_Tags,",")
| mvexpand PR_Tags
| dedup PR_Tags

That's my search, it shouldn't be returning the term PR_Tags. 
Saw the file that I'm using for the search, the only time that mentions PR_Tags in the csv is in the header. Is there a way to remove the header?

 

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

So you have a field called PR_Tags, with a value of "PR_Tags"?

index= host=  sourcetype=csv source=C:\\
| table PR_Tags
| where PR_Tags != "PR_Tags"
0 Karma

KalebeRS
Explorer

It worked, thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...