I have a search that is looking for IDS events. I want to exclude some known src and dest IP's for count = x. So my lookup file will be like this.
So how to i do the search and exclude where the items in the lookup exist in the search.
Thanks for any help....
Maybe a non inclusive subsearch?
your_search_for_ids [|inputlookup your_lookup.csv append=f| fields src dest|format "NOT (" "(" "" ")" "OR" ")"]
The NOT in the format command will tell the main search to NOT use the src AND dest from the lookup. So if your lookup is:
Then the subsearch evaluates to NOT ((src="server1" AND dest="server2")OR(src="server2" AND dest="server3") )
NOT ((src="server1" AND dest="server2")OR(src="server2" AND dest="server3") )