Splunk Enterprise Security

How to set priority and field in Splunk dashboard?

hkarthikeyan
New Member
 
Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Can you provide more information on what it is you're trying to do - that one line question doesn't provide any context.

 

0 Karma

hkarthikeyan
New Member

After loading the log file, we get one log entry as "Connection refused( which is an error message). In our Splunk indexing, we want to suppress these particular ones based on their "Category". How to do this ? 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

What have you done so far? It very much depends on the fields you have in your data, where this 'Connection refused' message can be found.

In the simple search case, you can just do 

your_search... NOT "Connection refused"

but that is not a very efficient search and is the most basic of solutions. 

If you want to be able to select to exclude those messages, then you would need some sort of input on your dashboard, but that will depend on what you have and more precisely the workflow you are trying to implement.

 

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...