Upgrade & Secure Your Future with DevOps, SRE, DevSecOps, MLOps!

We spend hours on Instagram and YouTube and waste money on coffee and fast food, but won’t spend 30 minutes a day learning skills to boost our careers.
Master in DevOps, SRE, DevSecOps & MLOps!

Learn from Guru Rajesh Kumar and double your salary in just one year.


Get Started Now!

How to filter out specific sources, sourcetypes, and hosts in Splunk?

Problem:
How to filter out specific sources, sourcetypes, and hosts from displaying on my Search Summary page in Splunk?

Sample Data – https://www.devopsschool.com/tutorial/splunk/labs/sample-data/earthquake/all_month_earthquakes.csv

Including or excluding or filter out specific sources, sourcetypes, and hosts in Splunk can be done with following.

  • Expressions within parentheses
  • NOT clauses
  • OR clauses
  • AND clauses

Examle QUERY


source="*"
source="all_month_earthquakes.csv" 
source="all_month_earthquakes.csv" NOT source="mypc-secruity.csv"
source="mypc-secruity.csv" NOT source="all_month_earthquakes.csv" 
NOT source="mypc-secruity.csv" source="all_month_earthquakes.csv"
source="all_month_earthquakes.csv" | search NOT source="mypc-secruity.csv"
source="mypc-secruity.csv" AND source="all_month_earthquakes.csv"
source="mypc-secruity.csv" OR source="all_month_earthquakes.csv"