If you create a search to watch network traffic and you wish to ignore a listing of /32 Destination IPs, would you create a macro of those IPs (ie: dest_ip=10.0.0.1/32) and then use
the NOT function in the search? For example:
Macro = whitelist
Search = index=generic NOT whitelist
Would this setup filter out all the IPs listed in the macro?
Yes. But to call the macro you need backtacks NOT `whitelist`.
Thanks. I actually do have the backtacks, but for some reason they aren't displaying in the Question. When I go to edit it, they appear and then disappear when saved. Weird. 🙂
AnyHoo... Thanks for the confirmation.