Splunk Search

Create a list

rootadmin
New Member

Hi

Im very new to splunk (first day using it)

Is it possible to create a list of known mac addresses so that i can perform a search

so at the moment im searching for new wireless client associations against the router, i would like to put existing wireless clients into a list of known mac addresses to include a not statement to account for known mac addresses.

have this working currently by explicitly mentioning each mac address in the not statement

Tags (1)
0 Karma

MHibbin
Influencer

You can do this using a lookup table (CSV) stored on the host server.

http://docs.splunk.com/Documentation/Splunk/5.0.3/Knowledge/Addfieldsfromexternaldatasources

You can then use a combination of an inputlookup command and subsearch in your search to filter these out.

http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Inputlookup
http://docs.splunk.com/Documentation/Splunk/latest/Search/Aboutsubsearches

So (if my memory is correct - not done this is a little while), you could do something like:

<yourBaseSearch> NOT [|inputlookup <lookupFile> | fields + mac]

Hope this helps,

MHibbin

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...