Splunk Enterprise

splunk spl - exclude multiple values

iherb_0718
Path Finder

Hello 

I have this query that works to exclude IP 5.5.5.5 from the list.

index=blah event.ts_detail=*blahblah* event.src_ip!=5.5.5.5

Now I want to also exclude 5.5.5.6.  What would I append to the syntax to accomplish this?
Basically, if the event.src_IP is 5.5.5.5 OR 5.5.5.6 I don't want it to trigger this alert. 

Labels (1)
0 Karma
1 Solution

to4kawa
Ultra Champion
index=blah event.ts_detail=*blahblah* NOT (event.src_ip IN ("5.5.5.5","5.5.5.6"))

e.g. https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Search#Comparison_expression_opt...

View solution in original post

0 Karma

to4kawa
Ultra Champion
index=blah event.ts_detail=*blahblah* NOT (event.src_ip IN ("5.5.5.5","5.5.5.6"))

e.g. https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Search#Comparison_expression_opt...

0 Karma
Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Community Content Calendar, October Edition

Welcome to the October edition of our Community Spotlight! The Splunk Community is a treasure trove of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...