Hello Splunkers,
Trying to fix the Web data models in the CIM and would like to exclude a couple of IP addresses. However, I'm struggling to form a white list for those specific IP addresses.
I'm looking for any guidance links and resources towards creating whitelists, all help is appreciated.
Thanks, and Happy Splunking!
Do you want to exclude IP's getting into datamodel? I would suggest to have IPs (e.g. src_ip) in the datamodel and have a category, say (web_blacklist_ips) in your asset data for those IPs. You can then create searches to exclude those Ips using the category.