Splunk Search

Skip lines while indexing

FRoth
Contributor

I am currently experimenting with the nmap scan output format and indexing the scan results with splunk.

I noticed that I got a lot of lines containing "Nmap scan report for 57.57.223.255 [host down]" which means that the line does not contain any useful information for me. I would like to skip all lines containing "host down".

Is there a hack to achieve this?

0 Karma
1 Solution

Ayn
Legend

There is specific functionality for filtering incoming logs, so I wouldn't consider it a "hack" 🙂

Have a look at the following docs page that explains how to achieve this: http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad#Filter_event_data_and_...

View solution in original post

Ayn
Legend

There is specific functionality for filtering incoming logs, so I wouldn't consider it a "hack" 🙂

Have a look at the following docs page that explains how to achieve this: http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad#Filter_event_data_and_...

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...