Splunk Search

I have a graph displaying how many workstations have out of date virus definitions. How can I exclude certain systems from the count?

New Member

On my dashboard, I have a graph displaying how many workstations have out of date virus definitions. Several of these workstations are likely sitting on a shelf in the client room waiting to be redeployed. Is there a way to exclude these systems in Splunk for a more accurate virus definitions count? Thank you

0 Karma

Contributor

First of all, show your query in the dashboard, and explain what is the pattern or names of the undesired values.

Generally you could use "field!=pc1 field!=pc2..."

Like this:
index=.... ... field!=pc1 field!=pc2... |chart ...

0 Karma

SplunkTrust
SplunkTrust

Is there a way to identify these system (sitting in client room waiting for redpeloyment)? Do they report Splunk from there? What is the query that you're using in your dashboard?

0 Karma