Splunk Search

Defining variables or constants

Engager

I would like to be able to have a predefined variable or constant to run queries with by example

source="syslog" login ip!=OFFICEIPS

where OFFICEIPS is a set of ip's

that way it wont require for us to know all ips every time we do a search but just mantain a table or variable every time a new subnet is added

Tags (2)
0 Karma
1 Solution

Splunk Employee
Splunk Employee

Splunk Employee
Splunk Employee

Engager

Thx will give it a shot!

0 Karma