Splunk Enterprise Security

How do I exclude a specific field value from search results?

shiroyasha_
New Member

I'm trying to exclude a specific value from my search result, what I'm currently getting is the list of top hosts using this query

sourcetype=akamaisiem | timechart  count by httpMessage.host

From my query I'm getting all the hostnames, how do I exclude a specific value from the results?

0 Karma

renjith_nair
Legend

@shiroyasha_ ,

You can exclude the host before the timechart

 sourcetype=akamaisiem 'httpMessage.host' !="unwanted host" | timechart  count by httpMessage.host
---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...