Splunk Search

exclude logs from being tagged

ahmadjabr
Engager

Hello,

I'm trying to eliminate the "unknown action, hosts" etc. there is some log's that don't contain an Action, so its counted as an unknown action, how could I stop this log's from being tagged at the wrong tag?

Regards

Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi @ahmadjabr,

One method is to exclude those hosts using <your search> action!=unknown otherwise if you do not want unknown in action field then you need to refine your search query so it will not generate unknown result in action but this is purely depend on your raw data and app/add-on which you are using which is generating action field.

Can you please let us know what type of logs are you searching and which app/add-on are you using to generate action field?

Thanks,
Harshil

View solution in original post

harsmarvania57
Ultra Champion

Hi @ahmadjabr,

One method is to exclude those hosts using <your search> action!=unknown otherwise if you do not want unknown in action field then you need to refine your search query so it will not generate unknown result in action but this is purely depend on your raw data and app/add-on which you are using which is generating action field.

Can you please let us know what type of logs are you searching and which app/add-on are you using to generate action field?

Thanks,
Harshil

wenthold
Communicator

Is this in reference to the CIM datamodels?

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...