Splunk Enterprise Security

How to set priority and field in Splunk dashboard?

hkarthikeyan
New Member
 
Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Can you provide more information on what it is you're trying to do - that one line question doesn't provide any context.

 

0 Karma

hkarthikeyan
New Member

After loading the log file, we get one log entry as "Connection refused( which is an error message). In our Splunk indexing, we want to suppress these particular ones based on their "Category". How to do this ? 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

What have you done so far? It very much depends on the fields you have in your data, where this 'Connection refused' message can be found.

In the simple search case, you can just do 

your_search... NOT "Connection refused"

but that is not a very efficient search and is the most basic of solutions. 

If you want to be able to select to exclude those messages, then you would need some sort of input on your dashboard, but that will depend on what you have and more precisely the workflow you are trying to implement.

 

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...