Knowledge Management

Using Splunk on a Mac - Currently Have Over 5,000 Sources - Help!

New Member

I've been using the beleaf app to develop my Splunk knowledge. I've noticed that I am unable to control the Sources and Hosts. Is there a way to limit (aside from a search query) to prevent unwanted data in my results? Thanks!!

Tags (1)
0 Karma

New Member

mayurr98, Thank you for your response. I will work on this over the weekend and get back to you. Thanks!!!

0 Karma

Super Champion

hey @ericrdecker
There are two ways to do this:

1)One way to prevent unwanted data is Discard specific events and keep the rest

have a look at this doc

2) Another way is to blacklist the files at index time and index only specific file you want!
Refer this doc for the same

let me know if this helps!

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...