Hi floks,
i have exclude dest IP from search which is working fine but in correlation it is still triggering alert.
search NOT [ | inputlookup sample.csv | fields dest_ip
Thanks
Hi @DawoodUlex,
This could be a permission issue. Go to the search page from enterprise security app and try running your search. It could be that your lookup is not accessible for ES.
If that's the case then all you have to do is move it into ES.
Cheers.
David
Thanks David.
Working fine now.
Dawood
Hi @DawoodUlex,
This could be a permission issue. Go to the search page from enterprise security app and try running your search. It could be that your lookup is not accessible for ES.
If that's the case then all you have to do is move it into ES.
Cheers.
David