Splunk Search

Create a list

rootadmin
New Member

Hi

Im very new to splunk (first day using it)

Is it possible to create a list of known mac addresses so that i can perform a search

so at the moment im searching for new wireless client associations against the router, i would like to put existing wireless clients into a list of known mac addresses to include a not statement to account for known mac addresses.

have this working currently by explicitly mentioning each mac address in the not statement

Tags (1)
0 Karma

MHibbin
Influencer

You can do this using a lookup table (CSV) stored on the host server.

http://docs.splunk.com/Documentation/Splunk/5.0.3/Knowledge/Addfieldsfromexternaldatasources

You can then use a combination of an inputlookup command and subsearch in your search to filter these out.

http://docs.splunk.com/Documentation/Splunk/5.0.3/SearchReference/Inputlookup
http://docs.splunk.com/Documentation/Splunk/latest/Search/Aboutsubsearches

So (if my memory is correct - not done this is a little while), you could do something like:

<yourBaseSearch> NOT [|inputlookup <lookupFile> | fields + mac]

Hope this helps,

MHibbin

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...