Splunk Enterprise Security

Exclude a Region/Country

codeJesus
Engager

 

Hello, 

when I run the below SPL , it gave me all the region that a user have accessed from. if I want to exclude a region or country from the list, please where do I add the SPL query and what is the SPL. I have used several exclusion query but it didn't work. please help 

 

 

| tstats count(Authentication.user) FROM datamodel=Authentication WHERE (index=* OR index=*) BY Authentication.action Authentication.src
| rename Authentication.* AS *
| iplocation src
| where len(Country)>0 AND len(City)>0

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

What have you tried so far and what do you mean by "didn't work"?

0 Karma

codeJesus
Engager

i added the below to get what I want.

| search Country!=<country name>

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...