Splunk Search

exclude logs from being tagged

ahmadjabr
Engager

Hello,

I'm trying to eliminate the "unknown action, hosts" etc. there is some log's that don't contain an Action, so its counted as an unknown action, how could I stop this log's from being tagged at the wrong tag?

Regards

Tags (1)
0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi @ahmadjabr,

One method is to exclude those hosts using <your search> action!=unknown otherwise if you do not want unknown in action field then you need to refine your search query so it will not generate unknown result in action but this is purely depend on your raw data and app/add-on which you are using which is generating action field.

Can you please let us know what type of logs are you searching and which app/add-on are you using to generate action field?

Thanks,
Harshil

View solution in original post

harsmarvania57
Ultra Champion

Hi @ahmadjabr,

One method is to exclude those hosts using <your search> action!=unknown otherwise if you do not want unknown in action field then you need to refine your search query so it will not generate unknown result in action but this is purely depend on your raw data and app/add-on which you are using which is generating action field.

Can you please let us know what type of logs are you searching and which app/add-on are you using to generate action field?

Thanks,
Harshil

wenthold
Communicator

Is this in reference to the CIM datamodels?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...