Knowledge Management

Using Splunk on a Mac - Currently Have Over 5,000 Sources - Help!

ericrdecker
New Member

I've been using the beleaf app to develop my Splunk knowledge. I've noticed that I am unable to control the Sources and Hosts. Is there a way to limit (aside from a search query) to prevent unwanted data in my results? Thanks!!

Tags (1)
0 Karma

ericrdecker
New Member

mayurr98, Thank you for your response. I will work on this over the weekend and get back to you. Thanks!!!

0 Karma

mayurr98
Super Champion

hey @ericrdecker
There are two ways to do this:

1)One way to prevent unwanted data is Discard specific events and keep the rest

have a look at this doc
http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Forwarding/Routeandfilterdatad#Discard_specif...

2) Another way is to blacklist the files at index time and index only specific file you want!
Refer this doc for the same
https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Data/Whitelistorblacklistspecificincomingdat...

let me know if this helps!

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...