Splunk Enterprise Security

How to set priority and field in Splunk dashboard?

hkarthikeyan
New Member
 
Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Can you provide more information on what it is you're trying to do - that one line question doesn't provide any context.

 

0 Karma

hkarthikeyan
New Member

After loading the log file, we get one log entry as "Connection refused( which is an error message). In our Splunk indexing, we want to suppress these particular ones based on their "Category". How to do this ? 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

What have you done so far? It very much depends on the fields you have in your data, where this 'Connection refused' message can be found.

In the simple search case, you can just do 

your_search... NOT "Connection refused"

but that is not a very efficient search and is the most basic of solutions. 

If you want to be able to select to exclude those messages, then you would need some sort of input on your dashboard, but that will depend on what you have and more precisely the workflow you are trying to implement.

 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...