Knowledge Management

Using Splunk on a Mac - Currently Have Over 5,000 Sources - Help!

ericrdecker
New Member

I've been using the beleaf app to develop my Splunk knowledge. I've noticed that I am unable to control the Sources and Hosts. Is there a way to limit (aside from a search query) to prevent unwanted data in my results? Thanks!!

Tags (1)
0 Karma

ericrdecker
New Member

mayurr98, Thank you for your response. I will work on this over the weekend and get back to you. Thanks!!!

0 Karma

mayurr98
Super Champion

hey @ericrdecker
There are two ways to do this:

1)One way to prevent unwanted data is Discard specific events and keep the rest

have a look at this doc
http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Forwarding/Routeandfilterdatad#Discard_specif...

2) Another way is to blacklist the files at index time and index only specific file you want!
Refer this doc for the same
https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Data/Whitelistorblacklistspecificincomingdat...

let me know if this helps!

0 Karma
Get Updates on the Splunk Community!

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

[Coming Soon] Splunk Observability Cloud - Enhanced navigation with a modern look and ...

We are excited to introduce our enhanced UI that brings together AppDynamics and Splunk Observability. This is ...