# Removing a specific firmware type from a query/ Grafana alert

**URL:** https://community.influxdata.com/t/removing-a-specific-firmware-type-from-a-query-grafana-alert/57372
**Category:** Systems
**Tags:** influxdb, grafana, flux
**Created:** [June 4, 2025, 7:48pm UTC](https://community.influxdata.com/t/removing-a-specific-firmware-type-from-a-query-grafana-alert/57372 "2025-06-04T19:48:27Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Celeste](https://sea1.discourse-cdn.com/flex023/user_avatar/community.influxdata.com/celeste/32/17011_2.png) [@Celeste](https://community.influxdata.com/u/Celeste)
#### Post date: [June 4, 2025, 7:48pm UTC](https://community.influxdata.com/t/removing-a-specific-firmware-type-from-a-query-grafana-alert/57372/1 "2025-06-04T19:48:28Z")

</div>

Hi. I am using influx db 2 and coding in flux to make an alert in Grafana.  
I am trying to remove certain devices with certain firmwares from the alert. The firmware I need to remove has a -p at the end.

I have tried so many things that don’t work.

Start Code:  
from(bucket: “BB”)  
|\> range(start: v.timeRangeStart, stop: v.timeRangeStop)

|\> filter(fn: (r) =\> r.\_measurement == “d” or r.\_measurement == “o”)  
|\> filter(fn: (r) =\> r.\_field == “dis” or r.\_field == “fw”)

//Exclude partner firmware, things I have tried:

|\> filter(fn: (r) =\> r[“fw”] !~ /-p/) // Exclude devices where fw contains “-p” using regex  
//|\> filter(fn: (r) =\> r.\_field != “fw” or r.\_value !~ /-p/)  
//|\> filter(fn: (r) =\> not (r.\_field == “fw” and r.\_value =~ /-p$/))

…  
(The rest of the code works great to give the alert that is managed by the variable dis. I just want to take out the devices with firmware -p.)

End Code.

Thanks.

---

<div class="post-metadata">

### Author: ![grant1](https://sea1.discourse-cdn.com/flex023/user_avatar/community.influxdata.com/grant1/32/15107_2.png) [@grant1](https://community.influxdata.com/u/grant1)
#### Post date: [June 5, 2025, 12:08am UTC](https://community.influxdata.com/t/removing-a-specific-firmware-type-from-a-query-grafana-alert/57372/2 "2025-06-05T00:08:28Z")

</div>

Hi @Celeste

Maybe this?

```auto
import "regexp" // not totally sure this is needed, but whatever

from(bucket: "BB")
|> range(start: v.timeRangeStart, stop: v.timeRangeStop)
|> filter(fn: (r) => r._measurement == "d" or r._measurement == "o")
|> filter(fn: (r) => r._field == "dis" or r._field == "fw")
|> filter(fn: (r) => 
    if r._field == "fw" then
        not regexp.matchRegexpString(r: /-p$/, v: r._value)
    else
        true
)

```

where

- `r`: the regex pattern `/-p$`
- `v`: the value to test (`r._value`)

---

<div class="post-metadata">

### Author: ![Celeste](https://sea1.discourse-cdn.com/flex023/user_avatar/community.influxdata.com/celeste/32/17011_2.png) [@Celeste](https://community.influxdata.com/u/Celeste)
#### Post date: [June 5, 2025, 5:46pm UTC](https://community.influxdata.com/t/removing-a-specific-firmware-type-from-a-query-grafana-alert/57372/3 "2025-06-05T17:46:54Z")

</div>

Hi Grant, Thank you!  
I get this error: [sse.dataQueryError] failed to execute query [A]: invalid: runtime error @11:6-16:4: filter: type conflict: string != float

fw is a string

---

<div class="post-metadata">

### Author: ![grant1](https://sea1.discourse-cdn.com/flex023/user_avatar/community.influxdata.com/grant1/32/15107_2.png) [@grant1](https://community.influxdata.com/u/grant1)
#### Post date: [June 5, 2025, 6:46pm UTC](https://community.influxdata.com/t/removing-a-specific-firmware-type-from-a-query-grafana-alert/57372/4 "2025-06-05T18:46:06Z")

</div>

Hi @Celeste

How about this?

```auto
import "regexp"

from(bucket: "BB")
  |> range(start: v.timeRangeStart, stop: v.timeRangeStop)
  |> filter(fn: (r) => r._measurement == "d" or r._measurement == "o")
  |> filter(fn: (r) => r._field == "dis" or r._field == "fw")
  |> filter(fn: (r) => 
    if r._field == "fw" then 
      not regexp.matchRegexpString(r: /-p$/, v: string(v: r._value))
    else 
      true
  )

```

---

<div class="post-metadata">

### Author: ![Celeste](https://sea1.discourse-cdn.com/flex023/user_avatar/community.influxdata.com/celeste/32/17011_2.png) [@Celeste](https://community.influxdata.com/u/Celeste)
#### Post date: [June 5, 2025, 9:07pm UTC](https://community.influxdata.com/t/removing-a-specific-firmware-type-from-a-query-grafana-alert/57372/5 "2025-06-05T21:07:32Z")

</div>

Ooo. I think it is working. If I find otherwise I’ll let you know.  
Thank you Grant!

---

<div class="post-metadata">

### Author: ![Celeste](https://sea1.discourse-cdn.com/flex023/user_avatar/community.influxdata.com/celeste/32/17011_2.png) [@Celeste](https://community.influxdata.com/u/Celeste)
#### Post date: [June 9, 2025, 8:59pm UTC](https://community.influxdata.com/t/removing-a-specific-firmware-type-from-a-query-grafana-alert/57372/6 "2025-06-09T20:59:27Z")

</div>

Hi Grant! This doesn’t work actually. Is there something different about the way flux functions inside a Grafana alert that I am missing? What is strange is I use “contains” to remove device id’s like this below and it works.

```auto
    // Exclude specific device_ids
    |> filter(fn: (r) => not contains(value: r.device_id, set: [
      "1",
      "2",
      "3",

```

But when I use contains to remove firmware versions, or other imported fields it doesn’t apply the filter.

---

<div class="post-metadata">

### Author: ![grant1](https://sea1.discourse-cdn.com/flex023/user_avatar/community.influxdata.com/grant1/32/15107_2.png) [@grant1](https://community.influxdata.com/u/grant1)
#### Post date: [June 10, 2025, 9:52am UTC](https://community.influxdata.com/t/removing-a-specific-firmware-type-from-a-query-grafana-alert/57372/7 "2025-06-10T09:52:44Z")

</div>

Can you share the full query that works (uses “contains” to remove device IDs) and also the full query that does not work (uses “contains” to remove firmware versions)? For the latter, does Grafana or InfluxDB give you an error?

I presume the 2nd query does not work in Influx Data Explorer either? Usually if the query works in Influx Data Explorer, it will work in Grafana. I have found that putting the same query into Grafana Alerting sometimes presents some challenges.
