Splunk Search

How to exclude some indexes from search?

Thomas19
New Member

Hi, I am encountering issue with 1 particular index. I am unable to use index!= to exclude the results from that particular index.

For example, I have 3 indexes - endpoint, server, mobile. I run a index=* index!=server index!=mobile [search parameters].

However, when the results came back, it is showing 2 indexes - endpoint and server.

That means the index!=mobile works, but not the index!=server. And I did verify without the index!= command, I will see all 3 indexes.

Of course this is a very simplified example with only 3 indexes but I am wondering, what could cause the index!=server not to work. In my current setup, all other indexes (I tested 10) work with index!= command but not that particular one.

Thanks.

Labels (1)
Tags (3)
0 Karma

yuanliu
SplunkTrust
SplunkTrust

Is it possible that the string "server" is not the precise index name?  Try search index=server alone to see if you get anything back.

As a side, you do not to add index=* in search string.  Additionally, you can probably use "NOT index IN (endpoint, mobile)" to make code more compact.

0 Karma

Thomas19
New Member

Thanks. Ya, the server is the precise index. Running index=server only return a single index

I tested the NOT IN, removed the index=*, still the same result. That particular index keep showing up - it works for all other indexes except for that - tested with many different indexes. So I suspect something is different with that index, just that I couldn't figure out the root cause.

0 Karma

yuanliu
SplunkTrust
SplunkTrust

A second test could be index!=*server*.

As you tested, all the side notes do not contribute to the essentials:-)

0 Karma
Get Updates on the Splunk Community!

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...