Getting Data In

Way to exclude ingestion of events for a specific IP address from a SourceType?

elvis5
Loves-to-Learn Lots

When I try use :

transforms.conf

[setnull]
 REGEX = 192\.168\.1\.50, 172\.16\.1\.50
 DEST_KEY = queue
 FORMAT = nullQueue

 props.conf

 [cisco]
 TRANSFORMS-null = setnull

 In event I get all result. But when I use  only one ip its woks good. If any way for exclude more than one ip. 

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @elvis5,

it's a regex, you have to use pipe ("|") as OR condition, not comma separated values:

[setnull]
 REGEX = (192\.168\.1\.50)|(172\.16\.1\.50)
 DEST_KEY = queue
 FORMAT = nullQueue
 props.conf

Ciao.

Giuseppe

0 Karma

elvis5
Loves-to-Learn Lots

Thanks it works!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @elvis5,

if one answer solves your need, please accept one answer for the other people of Community or tell me how I can help you.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...