Getting Data In

Way to exclude ingestion of events for a specific IP address from a SourceType?

elvis5
Loves-to-Learn Lots

When I try use :

transforms.conf

[setnull]
 REGEX = 192\.168\.1\.50, 172\.16\.1\.50
 DEST_KEY = queue
 FORMAT = nullQueue

 props.conf

 [cisco]
 TRANSFORMS-null = setnull

 In event I get all result. But when I use  only one ip its woks good. If any way for exclude more than one ip. 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @elvis5,

it's a regex, you have to use pipe ("|") as OR condition, not comma separated values:

[setnull]
 REGEX = (192\.168\.1\.50)|(172\.16\.1\.50)
 DEST_KEY = queue
 FORMAT = nullQueue
 props.conf

Ciao.

Giuseppe

0 Karma

elvis5
Loves-to-Learn Lots

Thanks it works!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @elvis5,

if one answer solves your need, please accept one answer for the other people of Community or tell me how I can help you.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2025 SplunkTrust is officially open! If you ...

Splunk Answers Content Calendar, June Edition II

Get ready to dive into Splunk Dashboard panels this week! We'll be tackling common questions around ...

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...