Getting Data In

Filter using a lookup.

aly347774
Loves-to-Learn Lots

I want to write a query whose purpose is to print for users who are not authorized to enter, and of course with the presence of a lookup table, the people who are authorized to enter are present in it.

Labels (5)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Please share some anonymised sample events to show what you are working with

0 Karma

aly347774
Loves-to-Learn Lots

index="(index name)" sourcetype=source type (host="host1" OR host="host2")
| search NOT [| inputlookup (lookup table name ) | table username] action=success | stats values(username) as user

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

OK it looks like it should work - what is your question?

0 Karma

aly347774
Loves-to-Learn Lots

It does not retrieve the blacklist, but rather it retrieves some of the whitelist. I want to make it pass through the lookuptable and show the user who is not authorized to enter.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

The principle of what you are doing is correct. So, if it is not working, it may come down to the actually data, which understandably you might not want to share. How are the values which are getting through different to the ones which are being removed? How large is your lookup table? Are there any special characters being used?

Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...