- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DawoodUlex
New Member
01-16-2020
03:41 AM
Hi floks,
i have exclude dest IP from search which is working fine but in correlation it is still triggering alert.
search NOT [ | inputlookup sample.csv | fields dest_ip
Thanks
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

DavidHourani
Super Champion
01-16-2020
04:05 AM
Hi @DawoodUlex,
This could be a permission issue. Go to the search page from enterprise security app and try running your search. It could be that your lookup is not accessible for ES.
If that's the case then all you have to do is move it into ES.
Cheers.
David
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DawoodUlex
New Member
01-20-2020
06:56 AM
Thanks David.
Working fine now.
Dawood
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

DavidHourani
Super Champion
01-16-2020
04:05 AM
Hi @DawoodUlex,
This could be a permission issue. Go to the search page from enterprise security app and try running your search. It could be that your lookup is not accessible for ES.
If that's the case then all you have to do is move it into ES.
Cheers.
David
