Splunk Enterprise Security

Splunk Web datamodel whitelisting

burakatabay
Path Finder

Hello Splunkers,

Trying to fix the Web data models in the CIM and would like to exclude a couple of IP addresses. However, I'm struggling to form a white list for those specific IP addresses.

I'm looking for any guidance links and resources towards creating whitelists, all help is appreciated.
Thanks, and Happy Splunking!

0 Karma

lakshman239
Influencer

Do you want to exclude IP's getting into datamodel? I would suggest to have IPs (e.g. src_ip) in the datamodel and have a category, say (web_blacklist_ips) in your asset data for those IPs. You can then create searches to exclude those Ips using the category.

0 Karma
Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques (Part 2)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Index This | What is the next number in the series? 7,645 5,764 4,576…

February 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Buttercup Games: Further Dashboarding Techniques

Hello! We are excited to kick off a new series of blogs from SplunkTrust member ITWhisperer, who demonstrates ...