Splunk Search

Elegant way of searching for all events where a field is not in a literal list of values

bobmorning
Engager

What is the most elegant way of searching for events where a field is not in a list of values?   For example:

index=foo | iplocation foo_src_ip |  search Country IN ("France", "United States")

works great.   

But what if I want all events where the IP was not from those countries (the  inverse answer), like "Canada", "Mexico".

Thanks for any assistance.

Bob

Tags (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try

index=foo | iplocation foo_src_ip |  search NOT Country IN ("France", "United States") 

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

Try

index=foo | iplocation foo_src_ip |  search NOT Country IN ("France", "United States") 
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...