Hi Everyone,
So we are using SPlunk Cloud and I have created a dashboard that searches for the top 100 most reoccurring messages coming in from out servers. After sifting through this list we pretty much eliminated about 70 of them as none important. Im having trouble with excluding these 70 common errors. I made a query that has a bunch of NOT statements but this isnt practical. I stumbled upon the inputlookup command and uploaded a .csv file that includes the 70 messages we dont care about. However, my search still doesn't seem to look at anything in the csv file. Does anyone have an suggestions?
My search string is:
index=* | inputlookup append=true exludedeerrors.csv | fields message | stats count by Message host index source | sort - count top limit=10
... View more