I'm following the example provided here.
search_time_range=alltime AND (NOT role=sc_admin) AND (NOT app=splunk_instance_monitoring)
However when I look in the monitoring console it shows that it's blocking some things that I believe are built in searches. (we use splunk cloud)
Cleanup Models For Predictive Analytics
Telemetry - Inputs
Telemetry - Volume
All of these things have user as "nobody". I tried to add AND (NOT user=nobody) to my workload rule, but tells me.
validation failed with error=invalid value of predicate 'user'