Splunk Enterprise Security

How to set priority and field in Splunk dashboard?

hkarthikeyan
New Member
 
Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Can you provide more information on what it is you're trying to do - that one line question doesn't provide any context.

 

0 Karma

hkarthikeyan
New Member

After loading the log file, we get one log entry as "Connection refused( which is an error message). In our Splunk indexing, we want to suppress these particular ones based on their "Category". How to do this ? 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

What have you done so far? It very much depends on the fields you have in your data, where this 'Connection refused' message can be found.

In the simple search case, you can just do 

your_search... NOT "Connection refused"

but that is not a very efficient search and is the most basic of solutions. 

If you want to be able to select to exclude those messages, then you would need some sort of input on your dashboard, but that will depend on what you have and more precisely the workflow you are trying to implement.

 

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...