Splunk Search

How to Modify Field to exclude field not needed?

jakeoftrades
Explorer

Hi,

Can anyone help me how can I change the field of my query to exclude those with 
PRODUCED labels

query:

index="hcg_ph_t2_bigdataservices_prod" sourcetype="be:streaming-services" earliest=-3h@h latest=@h
| search stream_type IN (Datascore_Compress, Datascore_Decompress, Eservices_Eload, Eservices_Ebills)
| eval service_details=stream_type." - ".kafka_datatype
| bucket span=90m _time
| stats sum(kafka_count) as count by _time service_details
| stats latest(count) as current_count earliest(count) as past_count by service_details

jakeoftrades_0-1652697442744.png

PRODUCED items which is under kafka_datatype:

jakeoftrades_1-1652697717311.png

 

I have tried to add this to my query but still does not exclude those with PRODUCED:

| sort .kafka_datatype asc
| fields - "PRODUCED"

Please help. 

Thank you,
Jake

Labels (3)
Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @jakeoftrades,

let me understand: you want to exclude results where kafka_datatype="PRODUCED", is this correct?

if this is your need, you could filter results in the main search of after the stats command, something like this:

index="hcg_ph_t2_bigdataservices_prod" sourcetype="be:streaming-services" earliest=-3h@h latest=@h stream_type IN (Datascore_Compress, Datascore_Decompress, Eservices_Eload, Eservices_Ebills) kafka_datatype!="PRODUCED"
| eval service_details=stream_type." - ".kafka_datatype
| bucket span=90m _time
| stats sum(kafka_count) as count by _time service_details
| stats latest(count) as current_count earliest(count) as past_count by service_details

in addition, you don't need to use the search command after the main search, in this way you have a slower search.

Ciao.

Giuseppe

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...