Splunk Search

How can i remove the particular user in table?

Sangeetha96
Engager

I have the below query:

| inputlookup test.csv
| eval epochtime=strptime(_time, "%a %b %d %H:%M:%S %Y")
| eval desired_time=strftime(epochtime, "%d/%m/%Y")
| rename desired_time as Date
| eval desired_time=strftime(epochtime, "%b%y'")
| rename desired_time as Month

 

am getting this output in user field.

user

Abcd101

sv23010

ns03621

here i want to remove the user sv48840,ns19075 row in this table.

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust
| where user!="sv48840" AND user!="ns19075"

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust
| where user!="sv48840" AND user!="ns19075"
0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...