Splunk Enterprise Security

Exclude a Region/Country

codeJesus
Engager

 

Hello, 

when I run the below SPL , it gave me all the region that a user have accessed from. if I want to exclude a region or country from the list, please where do I add the SPL query and what is the SPL. I have used several exclusion query but it didn't work. please help 

 

 

| tstats count(Authentication.user) FROM datamodel=Authentication WHERE (index=* OR index=*) BY Authentication.action Authentication.src
| rename Authentication.* AS *
| iplocation src
| where len(Country)>0 AND len(City)>0

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

What have you tried so far and what do you mean by "didn't work"?

0 Karma

codeJesus
Engager

i added the below to get what I want.

| search Country!=<country name>

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...