Hello,
I'm building a list of "known" IP addresses i want to exclude from a logon log search query (so it essentially just show me logon attempts from non-verified IP addresses) . Is there a way to reference a file i would maintain, in a query to make things easier?
I'm on Splunk Cloud
Thanks!
did some searching, uploading lookup table and using inputlookup command did the trick!
did some searching, uploading lookup table and using inputlookup command did the trick!