All I wanted was to see if the Palo Alto or the ASA’s were able to see any traffic from a specific IP address. Most of the result I am receiving are from Infoblox. I just need to know how to filter out InfoBlox to just see our ASA and Palo Alto.
Your Infoblox, ASA, and Palo Alto data should have different sourcetypes. Add NOT sourcetype=infoblox
to your query to filter out Infoblox events.