Limited Time Offer!

For Less Than the Cost of a Starbucks Coffee, Access All DevOpsSchool Videos on YouTube Unlimitedly.
Master DevOps, SRE, DevSecOps Skills!

Enroll Now

How to filter out specific sources, sourcetypes, and hosts in Splunk?

Problem:
How to filter out specific sources, sourcetypes, and hosts from displaying on my Search Summary page in Splunk?

Sample Data – https://www.devopsschool.com/tutorial/splunk/labs/sample-data/earthquake/all_month_earthquakes.csv

Including or excluding or filter out specific sources, sourcetypes, and hosts in Splunk can be done with following.

  • Expressions within parentheses
  • NOT clauses
  • OR clauses
  • AND clauses

Examle QUERY


source="*"
source="all_month_earthquakes.csv" 
source="all_month_earthquakes.csv" NOT source="mypc-secruity.csv"
source="mypc-secruity.csv" NOT source="all_month_earthquakes.csv" 
NOT source="mypc-secruity.csv" source="all_month_earthquakes.csv"
source="all_month_earthquakes.csv" | search NOT source="mypc-secruity.csv"
source="mypc-secruity.csv" AND source="all_month_earthquakes.csv"
source="mypc-secruity.csv" OR source="all_month_earthquakes.csv"
Rajesh Kumar
Follow me