Splunk Search

Ignore List in a Macro


If you create a search to watch network traffic and you wish to ignore a listing of /32 Destination IPs, would you create a macro of those IPs (ie: dest_ip= and then use
the NOT function in the search? For example:

Macro = whitelist
Search = index=generic NOT whitelist

Would this setup filter out all the IPs listed in the macro?

0 Karma

Super Champion

Yes. But to call the macro you need backtacks NOT `whitelist`.


Thanks. I actually do have the backtacks, but for some reason they aren't displaying in the Question. When I go to edit it, they appear and then disappear when saved. Weird. 🙂

AnyHoo... Thanks for the confirmation.

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!