Splunk Search

How to exclude some indexes from search?

Thomas19
New Member

Hi, I am encountering issue with 1 particular index. I am unable to use index!= to exclude the results from that particular index.

For example, I have 3 indexes - endpoint, server, mobile. I run a index=* index!=server index!=mobile [search parameters].

However, when the results came back, it is showing 2 indexes - endpoint and server.

That means the index!=mobile works, but not the index!=server. And I did verify without the index!= command, I will see all 3 indexes.

Of course this is a very simplified example with only 3 indexes but I am wondering, what could cause the index!=server not to work. In my current setup, all other indexes (I tested 10) work with index!= command but not that particular one.

Thanks.

Labels (1)
Tags (3)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Is it possible that the string "server" is not the precise index name?  Try search index=server alone to see if you get anything back.

As a side, you do not to add index=* in search string.  Additionally, you can probably use "NOT index IN (endpoint, mobile)" to make code more compact.

0 Karma

Thomas19
New Member

Thanks. Ya, the server is the precise index. Running index=server only return a single index

I tested the NOT IN, removed the index=*, still the same result. That particular index keep showing up - it works for all other indexes except for that - tested with many different indexes. So I suspect something is different with that index, just that I couldn't figure out the root cause.

0 Karma

yuanliu
SplunkTrust
SplunkTrust

A second test could be index!=*server*.

As you tested, all the side notes do not contribute to the essentials:-)

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...