Splunk Search

How to exclude some indexes from search?

Thomas19
New Member

Hi, I am encountering issue with 1 particular index. I am unable to use index!= to exclude the results from that particular index.

For example, I have 3 indexes - endpoint, server, mobile. I run a index=* index!=server index!=mobile [search parameters].

However, when the results came back, it is showing 2 indexes - endpoint and server.

That means the index!=mobile works, but not the index!=server. And I did verify without the index!= command, I will see all 3 indexes.

Of course this is a very simplified example with only 3 indexes but I am wondering, what could cause the index!=server not to work. In my current setup, all other indexes (I tested 10) work with index!= command but not that particular one.

Thanks.

Labels (1)
Tags (3)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Is it possible that the string "server" is not the precise index name?  Try search index=server alone to see if you get anything back.

As a side, you do not to add index=* in search string.  Additionally, you can probably use "NOT index IN (endpoint, mobile)" to make code more compact.

0 Karma

Thomas19
New Member

Thanks. Ya, the server is the precise index. Running index=server only return a single index

I tested the NOT IN, removed the index=*, still the same result. That particular index keep showing up - it works for all other indexes except for that - tested with many different indexes. So I suspect something is different with that index, just that I couldn't figure out the root cause.

0 Karma

yuanliu
SplunkTrust
SplunkTrust

A second test could be index!=*server*.

As you tested, all the side notes do not contribute to the essentials:-)

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...