Splunk Search

Exclude a result in search

djras123
Observer

I am trying to exclude this from a search. They are almost all the same just the sshd instance changes can someone help me exclude?

ras1-dan-cisco-swi error: PAM: Authentication failure for illegal user djras123 from 192.168.1.2 - dcos_sshd[17284]
ras1-dan-cisco-swi error: PAM: Authentication failure for illegal user djras123 from 192.168.1.2 - dcos_sshd[29461]
ras1-dan-cisco-swi error: PAM: Authentication failure for illegal user djras123 from 192.168.1.2 - dcos_sshd[4064]
ras1-dan-cisco-swi error: PAM: Authentication failure for illegal user djras123 from 192.168.1.2 - dcos_sshd[9450]

Thanks guys besides excluding each one,

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

While you could do an explicit exclusion as @marnall already showed it's probably not the most effective solution. Remember that by default inclusion is better than exclusion.

So the question is whether the events you want to exclude differ significantly from those you include? (Of course the best thing would be if you could differentiate them by an indexed field).

0 Karma

marnall
Motivator

While not the most computationally efficient, you could use a negating keyword search for the string you would like to exclude:

<yourSPL> NOT "PAM: Authentication failure for illegal user djras123 from"

Or have it on a separate search line, if your SPL does not end on a "search" command:

<yourSPL>
| search NOT "PAM: Authentication failure for illegal user djras123 from"
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...