Splunk Search

Exclude a Country with geoip

Path Finder


I have the following search
index=collaboration sourcetype="mail-2" Auth | geoip simta_client_ip | dedup simta_smtp_authuser | table simta_smtp_authuser simta_client_ip_country_name

I would like to exclude the "United States" from the countries returned. Its probably easy but I cannot seem to find a way to do it.

thanks for the help!

Tags (2)
0 Karma

Ultra Champion

... | where field != value

in your case probably something like

where simta_client_ip_country_name != "United States"



Thanks @kristian.kolb

0 Karma