Splunk Search

Boolean query to exclude value in Filter Lookup

mojoes
Engager

Hi, I am new at Splunk and I'm following the lab in Enriching Data with Lookups, where I'm requested to exclude a value using the Flter Lookup. I have a Lookup definition based on knonwusers.csv

In the video it doesn't explain or show any example for this specific field. I have tried the following:

user NOT (root OR mail OR apache)
user <> (root OR mail OR apache)
|inputlookup knownusers.csv |eval user NOT (root OR mail OR apache)

And nothing is working. Could you please tell me what am I doing wrong? 

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

You could do something like this

| inputlookup knownusers.csv
| where NOT user IN ("root", "mail", "apache")

Although this might not be classed a filtering using a lookup.

Assuming you have a user field in your events, you could filter them like this

| lookup knownusers.csv user OUTPUT user AS found_user
| where isnull(found_user)

View solution in original post

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

You could do something like this

| inputlookup knownusers.csv
| where NOT user IN ("root", "mail", "apache")

Although this might not be classed a filtering using a lookup.

Assuming you have a user field in your events, you could filter them like this

| lookup knownusers.csv user OUTPUT user AS found_user
| where isnull(found_user)
0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...