Sample Queries for Filtering Records
You can use the following sample queries as a reference or example to create your own queries and filter records.
Sample Queries
Exclude Specific Hosts
Query:
host.name.keyword:(NOT hdp1001.qe.iti.acceldata.dev hdp1002.qe.iti.acceldata.dev)
This example shows how to filter out particular hosts from your search results in Pulse.
- Field:
– the field you are filtering onhost.name.keyword - Operator:
– excludes the specified valuesNOT - Values:
– the hosts to excludehdp1001.qe.iti.acceldata.dev hdp1002.qe.iti.acceldata.dev
You can list multiple hosts, separated by spaces, and all of them will be excluded from the results.
Exclude Specific Sources
Query:
source:(NOT state-change.log server.log)
This example shows how to filter out particular log sources from your search results in Pulse.
- Field:
– filter by log sourcesource - Operator:
– exclude the specified valuesNOT - Values:
– the sources you want to exclude.state-change.log server.log
Exclude Specific Services
Query:
fields.component:(NOT yarn_application kafka_server_gc)
This example shows how to filter out particular services from your search results in Pulse.
- Field:
– filter by service/componentfields.component - Operator:
– excludes the specified valuesNOT - Values:
– the services to excludeyarn_application kafka_server_gc
Exclude Specific Log Levels
Query:
loglevel:(NOT INFO WARN)
This example shows how to filter out particular log levels from your search results in Pulse.
- Field:
– filter by log severityloglevel - Operator:
– excludes the specified valuesNOT - Values:
– the log levels to excludeINFO WARN
Exclude or Include Log Messages With Certain Keywords
Query:
message:(+exception -connection)
This example shows how to filter log messages that contain specific keywords in Pulse search results.
- Field:
– filter by log message contentmessage - Operator:
– include messages containing this term+ - Operator:
– exclude messages containing this term- - Values:
(included),exception(excluded)connection
Combine Multiple Filters
Query:
host.name.keyword:(NOT hdp1001.qe.iti.acceldata.dev hdp1002.qe.iti.acceldata.dev)
AND source:(NOT state-change.log server.log)
AND fields.component:(NOT yarn_application kafka_server_gc)
AND loglevel:(NOT INFO WARN)
AND message:(+exception -connection)
This combined filter query enables you to refine results by multiple dimensions simultaneously: excluding specific hosts, sources, services, and log levels, while including/excluding specific keywords in the messages.

Have a suggestion?