Ignore List in a Macro


If you create a search to watch network traffic and you wish to ignore a listing of /32 Destination IPs, would you create a macro of those IPs (ie: dest_ip= and then use
the NOT function in the search? For example:

Macro = whitelist
Search = index=generic NOT whitelist

Would this setup filter out all the IPs listed in the macro?

Yes. But to call the macro you need backtacks NOT `whitelist`.


Thanks. I actually do have the backtacks, but for some reason they aren't displaying in the Question. When I go to edit it, they appear and then disappear when saved. Weird. 🙂

AnyHoo... Thanks for the confirmation.

