Splunk Enterprise Security

Exclude list of dest IP from search using input lookup but correlation is alerting excluded dest IP

DawoodUlex
New Member

Hi floks,

i have exclude dest IP from search which is working fine but in correlation it is still triggering alert.

search NOT [ | inputlookup sample.csv | fields dest_ip

Thanks

0 Karma
1 Solution

DavidHourani
Super Champion

Hi @DawoodUlex,

This could be a permission issue. Go to the search page from enterprise security app and try running your search. It could be that your lookup is not accessible for ES.

If that's the case then all you have to do is move it into ES.

Cheers.
David

View solution in original post

0 Karma

DawoodUlex
New Member

Thanks David.

Working fine now.

Dawood

0 Karma

DavidHourani
Super Champion

Hi @DawoodUlex,

This could be a permission issue. Go to the search page from enterprise security app and try running your search. It could be that your lookup is not accessible for ES.

If that's the case then all you have to do is move it into ES.

Cheers.
David

0 Karma
Get Updates on the Splunk Community!

What’s new on Splunk Lantern in August

This month’s Splunk Lantern update gives you the low-down on all of the articles we’ve published over the past ...

Welcome to the Future of Data Search & Exploration

You have more data coming at you than ever before. Over the next five years, the total amount of digital data ...

This Week's Community Digest - Splunk Community Happenings [8.3.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...