Splunk Search

How do I exclude a subnet from a search using CIDR notation?

jlawsonmers
New Member

How do I exclude a subnet from a search using CIDR notation? For example, I have this search:

"%ASA-4-733100" OR "%ASA-4-733104" OR "%ASA-4-733105" NOT "[ Scanning]" NOT "[   172.16.10.2]" NOT "[           DNS   53]" NOT "[  NetBIOS-Name  137]"

I would like to exclude 192.168.0.0/16 from this search. What is a simple way to do this?

Tags (1)
0 Karma

kristian_kolb
Ultra Champion
0 Karma

jlawsonmers
New Member

Should I use NOT "host_ip=192.168.0.0/16" or should I leave off the quotation marks?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...