- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Web datamodel whitelisting

burakatabay
Path Finder
03-29-2019
12:35 AM
Hello Splunkers,
Trying to fix the Web data models in the CIM and would like to exclude a couple of IP addresses. However, I'm struggling to form a white list for those specific IP addresses.
I'm looking for any guidance links and resources towards creating whitelists, all help is appreciated.
Thanks, and Happy Splunking!
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

lakshman239
Influencer
03-29-2019
03:52 AM
Do you want to exclude IP's getting into datamodel? I would suggest to have IPs (e.g. src_ip) in the datamodel and have a category, say (web_blacklist_ips) in your asset data for those IPs. You can then create searches to exclude those Ips using the category.
