Splunk Search

How to edit my search to filter out results that are present in lookup tables?

benmon
Explorer

Hi,

I need to filter the results that are present in the lookup tables. This search is what I have used:

index=* sourcetype="pan:threat" action=allowed | stats count(threat_name) by threat_name NOT [|inputlookup paloaltosignature | table signatures | rename signatures as threat_name]

but there are no results. I have checked the search separately and it is working.
Can somebody tell me what is the problem with the search?
Regards,

0 Karma

sundareshr
Legend

You are missing a search command before the NOT. Try this

index=* sourcetype="pan:threat" action=allowed | stats count(threat_name) by threat_name | search NOT [|inputlookup paloaltosignature | table signatures | rename signatures as threat_name]
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...