Splunk Enterprise

splunk spl - exclude multiple values

iherb_0718
Path Finder

Hello 

I have this query that works to exclude IP 5.5.5.5 from the list.

index=blah event.ts_detail=*blahblah* event.src_ip!=5.5.5.5

Now I want to also exclude 5.5.5.6.  What would I append to the syntax to accomplish this?
Basically, if the event.src_IP is 5.5.5.5 OR 5.5.5.6 I don't want it to trigger this alert. 

Labels (1)
0 Karma
1 Solution

to4kawa
Ultra Champion
index=blah event.ts_detail=*blahblah* NOT (event.src_ip IN ("5.5.5.5","5.5.5.6"))

e.g. https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Search#Comparison_expression_opt...

View solution in original post

0 Karma

to4kawa
Ultra Champion
index=blah event.ts_detail=*blahblah* NOT (event.src_ip IN ("5.5.5.5","5.5.5.6"))

e.g. https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Search#Comparison_expression_opt...

0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...