Splunk Search

Exclude a Country with geoip

brywilk_umich
Path Finder

Hello,

I have the following search
index=collaboration sourcetype="mail-2" Auth | geoip simta_client_ip | dedup simta_smtp_authuser | table simta_smtp_authuser simta_client_ip_country_name

I would like to exclude the "United States" from the countries returned. Its probably easy but I cannot seem to find a way to do it.

thanks for the help!

Tags (2)
0 Karma

kristian_kolb
Ultra Champion

... | where field != value

in your case probably something like

where simta_client_ip_country_name != "United States"

/k

saurabh_tek
Communicator

Thanks @kristian.kolb

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...