<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How Can I View IPs That Have NOT Generated Events? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154624#M43475</link>
    <description>&lt;P&gt;I don't think I can understand the requirement here? Does this search returns some field name with IP address and you want to exclude those IP from search results and show everything else??&lt;/P&gt;

&lt;P&gt;Shot in dark, try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=blah NOT [search index=blah dest_ip=10.0.0.0/16 | stats count by YourIPField | table YourIPField] | stats count by YourIPField
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 04 Aug 2015 20:31:03 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2015-08-04T20:31:03Z</dc:date>
    <item>
      <title>How Can I View IPs That Have NOT Generated Events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154622#M43473</link>
      <description>&lt;P&gt;For example, I want to run the following search and have splunk output IPs that do NOT show up in the results.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=blah dest_ip=10.0.0.0/16
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I imagine i need to use the stats count function but I have yet to figure it out.&lt;/P&gt;

&lt;P&gt;edit: I have a list of ~1600 hosts and I want to see which ones in this list have not generated any events.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2015 20:25:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154622#M43473</guid>
      <dc:creator>ErraticIncome93</dc:creator>
      <dc:date>2015-08-04T20:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: How Can I View IPs That Have NOT Generated Events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154623#M43474</link>
      <description>&lt;P&gt;For events, like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=blah NOT dest_ip=10.0.0.0/16
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=blah | regex dest_ip!=10.0.0.0/16
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;For just IPs, like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; index=blah NOT dest_ip=10.0.0.0/16 | stats values(dest_ip)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or, if I am being too literal, perhaps you need to make use of the above but &lt;EM&gt;ALSO&lt;/EM&gt; the &lt;CODE&gt;cidrmatch&lt;/CODE&gt; function:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions"&gt;http://docs.splunk.com/Documentation/Splunk/latest/SearchReference/CommonEvalFunctions&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2015 20:27:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154623#M43474</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-08-04T20:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: How Can I View IPs That Have NOT Generated Events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154624#M43475</link>
      <description>&lt;P&gt;I don't think I can understand the requirement here? Does this search returns some field name with IP address and you want to exclude those IP from search results and show everything else??&lt;/P&gt;

&lt;P&gt;Shot in dark, try this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=blah NOT [search index=blah dest_ip=10.0.0.0/16 | stats count by YourIPField | table YourIPField] | stats count by YourIPField
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 04 Aug 2015 20:31:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154624#M43475</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-08-04T20:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: How Can I View IPs That Have NOT Generated Events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154625#M43476</link>
      <description>&lt;P&gt;Say I have a list of 5 IPs: 10.0.0.1 - 10.0.0.5. I want to see which one of those 5 IPs have yet to generate an event. If I just exclude 10.0.0.0/16 I will get results for 172.1.1.1, 192.168.1.1, etc... if 10.0.0.3 was the only IP to not generate an event then I want 10.0.0.3 to be the only result from the splunk search.&lt;/P&gt;

&lt;P&gt;So 10.0.0.3 does not exist anywhere in a splunk index... maybe its not possible and I just need to pull all IPs that exist in a splunk field and then diff it against my list of IPs?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2015 20:36:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154625#M43476</guid>
      <dc:creator>ErraticIncome93</dc:creator>
      <dc:date>2015-08-04T20:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: How Can I View IPs That Have NOT Generated Events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154626#M43477</link>
      <description>&lt;P&gt;When you say you've list of IP's, I'm assuming that you've a string list of IPs which you want to check if they have any events from that IP. If this is correct try this (gentimes is just placeholder creator)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=blah [| gentimes start=-1 | eval dest_ip="Your comma separated IP list, e.g. IP1,IP2,... etc" | table dest_ip | makemv dest_ip delim="," | mvexpand dest_ip ] | stats count by dest_ip | eval Type="Have Events" | append [| gentimes start=-1 | eval dest_ip="Your comma separated IP list, e.g. IP1,IP2,... etc" | table dest_ip | makemv dest_ip delim="," | mvexpand dest_ip | eval Type="No Events"] | stats values(Type) as Type by dest_ip | where mvcount(Type)=1 AND  Type="No Events"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This should give you IP from your list of IP which don't have any events in Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2015 21:14:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154626#M43477</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-08-04T21:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: How Can I View IPs That Have NOT Generated Events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154627#M43478</link>
      <description>&lt;P&gt;Awesome, this is exactly what I needed. I tested it out with two bogus IPs over a 30 second period and it worked. Trying it now with a list of 1500 IPs and hoping it doesn't crash.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2015 15:06:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154627#M43478</guid>
      <dc:creator>ErraticIncome93</dc:creator>
      <dc:date>2015-08-05T15:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: How Can I View IPs That Have NOT Generated Events?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154628#M43479</link>
      <description>&lt;P&gt;Finally got it working...&lt;/P&gt;

&lt;P&gt;first, create a lookup table first with the IPs that I want to cross reference:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=nessus severity=critical | stats count by dest_ip | table dest_ip | outputlookup crit_vuln_hosts.csv
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;second, cross reference that table against all of my indexes except for the nessus one:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| inputlookup crit_vuln_hosts.csv | fields dest_ip | search NOT [ search index!=nessus | dedup dest_ip | fields dest_ip ]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 25 Aug 2015 13:23:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-Can-I-View-IPs-That-Have-NOT-Generated-Events/m-p/154628#M43479</guid>
      <dc:creator>ErraticIncome93</dc:creator>
      <dc:date>2015-08-25T13:23:52Z</dc:date>
    </item>
  </channel>
</rss>

